# Tandu Privacy Policy
**Version 2 - effective 19 August 2026.** *This is a courtesy translation. The
Hebrew version is the binding text; where the two differ, the Hebrew governs.*
Tandu Me LTD ("Tandu", "we") is an Israeli company operating an AI-based
matchmaking service. This document explains what information we collect about
you, what we do with it, who receives it, how long we keep it, and what you can
do about it. We wrote it to be understood, not to be long.
Information about a person's romantic life is especially sensitive under
Israel's Privacy Protection Law. That is exactly the kind of information this
service deals in, which is why we ask for your explicit, separate consent before
we learn anything about you.
## In short
- We collect what you tell the matchmaker in conversation, the photos you
share, and basic account details: name, email address, date of birth, phone
number and area of residence.
- **Several things here are safety measures.** A verified phone number makes
sure that one real person stands behind each account; approximate,
city-level location makes sure the offers you get are within a distance you
can actually act on, and catches an account that is not where it claims to
be; and we examine the photos - estimating age and gender from them, and
comparing them to one another to confirm they are all of the same person.
The comparison is automated: we use technological means to tell whether the
same person appears in the photos. Anything derived from the photos for this
check - biometric data included - is used only for this check within your
own account, is never compared against any external database, and is kept on
the photo's own record and deleted with it. Your number and your location are not
shown to any other user, and a machine's estimate never blocks you without a
person having looked.
- The matchmaker is **an AI**, not a person. It reads the conversation and
builds a profile from it, in order to find you the right person.
- Your conversation content is sent to an external language-model provider in
the United States, which generates the reply. These providers do not use your
content to train their models.
- **Authorised staff at Tandu can read your conversations with the
matchmaker** - for safety, support, and troubleshooting. A conversation
between you and a match is opened for review only if one of you reports the
other. Every such access is logged, and anyone with access is bound by a
written internal procedure.
- We **do not sell your information and do not share it for advertising** -
not today and not in the future.
- We **do not use your conversations to train or evaluate models**. If we want
to do so in the future, we will ask you for separate, explicit consent, and
you will be free to refuse without it affecting the service.
- You can at any time ask to see your information, correct it, delete your
account, or withdraw your consent.
- For anything privacy-related: **privacy@tandu.me**.
## 1. Who we are
Tandu Me LTD, a company registered in Israel, Klil HaHoresh 274, Nes Harim
9988500.
The company is the database owner and is responsible for the information.
Privacy enquiries go to **privacy@tandu.me**. We have not appointed a statutory
Privacy Protection Officer, because we are not among the bodies required to
appoint one; the duties themselves rest with a defined role here.
## 2. Giving us information is voluntary
You are under no legal obligation to give us information. But the service is
built on what you tell the matchmaker: without consent to process your
information for matchmaking we cannot operate the service for you, and without
a verified phone number and without access to your approximate location we
cannot present you with a match offer.
## 3. What we collect
**Account details.** You sign in with an existing Google or Apple account. From
that we receive an account identifier and an email address. We also store: a
name or nickname you choose for us to use, full date of birth, phone number and
when it was verified, the area of residence you tell us, time zone, and device
identifiers for notifications. **We do not ask for or store an identity
document.** If we conclude that verification against an identity document is
necessary for users' safety, we will not start doing it quietly: we will
publish a new version of this policy setting out exactly what is collected, who
sees it and how long it is kept, and ask for your consent again.
**Area of residence and device location.** The area you live in - a city or a
region - is something you tell the matchmaker in conversation, and we keep it
in order to suggest people who live within a distance you can act on. In
addition, the app asks for access to your device location at an approximate
level, and we compare it against the area you gave us - a consistency check
that helps identify accounts that are not who they present themselves to be.
**This permission is required in order to use the service:** without it we
cannot offer you matches, and if you revoke it in your device settings, offers
stop until you restore it.
We ask for **approximate location only, at city level** - not precise
location. We keep only your current location and not a movement history, and we
do not show it to any other user.
**Conversations with the matchmaker.** Everything written in the conversation is
stored. That includes anything you choose to share about your relationships,
preferences, family status, religion and worldview, and anything else that comes
up.
**Photos.** Photos you upload in conversation, including photos of yourself.
From photos in which a face is visible we derive two things for safety
purposes (see section 4(c)): an estimate of age and of gender, and a
comparison of your photos against one another - to confirm that they all show
the same person.
The comparison is automated: we use technological means (section 6) to tell
whether the same person appears in the photos and to estimate age from them.
Anything derived from your photos for this check - biometric data included -
is used solely for this purpose within your own account: it is not used to
identify you anywhere else, it is not compared against any external face
database, and we pass it to no one. It is held on the photo's own record and
deleted when the photo is deleted. The check's result in words - an age range,
an assessment of gender, whether the photos appear to be of one person, and a
short note - is kept the same way, and shown to you on request.
**Conversations with a match.** When you begin chatting in the app with someone
you have been matched with, that conversation is stored with us. The matchmaker
itself does not receive its contents - it sees only metadata about the
conversation (for example that it happened, and at what pace). We do not read
these conversations in the ordinary course, and no automated screening runs on
them. What opens such a conversation to review is a report: if either of you
reports the other, the conversation between you may be reviewed by our safety
team - and the report screen says so at the moment of reporting.
**Reports.** If you report another user - or another user reports you - we keep
the report: who reported whom, the reason chosen, anything written in it, and
what we decided on it. A report is information about both sides, and it is kept
under the safety exception in section 10.
**Information derived from all of the above.** From conversations and photos we
build your profile: profile facts (for example "looking for something serious",
"traditionally observant"), conversation summaries, and questions and answers
relayed between you and a match. We
hold ourselves to a simple rule: we do not keep information about you that we
would not be willing to show you.
**An impression from your photos.** From your photos we form an overall
impression of how you come across in them. The impression stays private, it is
used to suggest matches, and you receive it together with advice on how to
present yourself best in your photos.
**The consent record.** For every consent you give we keep a record: which
purpose, exactly which text was shown to you, in which language, exactly what
you replied, and when.
**Operational and control records.** System and error logs, performance metrics,
a record of every language-model call (model, token counts, cost - no content),
and audit records showing which staff member accessed what and when. These
records contain identifiers and numbers only, never conversation content.
**Paid subscription information.** Tandu Plus is purchased through the app store
(Apple or Google). **We never see or store payment details.** What reaches us is
subscription status and validity.
**What we don't do.** The app contains no advertising trackers, and we pass
nothing to advertisers, data brokers, or social networks.
## 4. Why we use the information, and on what basis
**a. Operating the service and matchmaking.** Running the conversation with the
matchmaker, building the profile, finding suitable candidates - including
matching by area of residence, so that the offers you get are within a distance
you can act on - presenting offers, relaying questions and answers between you
and a match, and running the conversation between the two sides. Basis:
performance of our agreement - this is the service you asked for.
**b. Processing sensitive information.** Learning your romantic and sexual
preferences and orientation, your family status, your religion and worldview,
and building your profile on that basis - for matchmaking. This includes the
photos you share, what is derived from them for the check, and the check's
result.
Basis: **your explicit consent**, which we request at the start of the
conversation - and which says explicitly that we examine the photos.
**c. Identity verification - a safety measure.** A verified phone number helps
us keep one real person behind each account. It prevents duplicate accounts and
impersonation, and it is what allows us to block someone who behaved badly
without their immediately opening a new account under another name. That is why
phone verification is a condition for receiving a match offer: we want you to
know that the person facing you passed the same check. It is not a condition
for talking to the matchmaker itself, and we do not show your number to any
other user.
Alongside it there are three further signals serving the same purpose: the
comparison between your device location and the area you gave us, the estimate
of age and gender derived from the photos, and the comparison of your photos
against one another. They are there to identify an account that is not who it
presents itself to be - a minor posing as an adult, or an account whose photos
are not of one person. **An estimate from a photo can be wrong, and so it is
never decisive on its own:** it flags an account for review, and the decision to
block or delete is a person's. If you were flagged by mistake, a single message
to privacy@tandu.me is enough for us to look again, and what you tell us about
yourself outweighs what the machine guessed.
**The phone and the location** rest on performance of our agreement - a service
that offers you people in your area cannot work without knowing where you are -
and alongside it on the legitimate interest of all users in a service that can
be relied on.
**Examining the photos** may involve biometric information: its basis is your
explicit consent under section 4(b), and the wording in which we ask for it says
explicitly that we examine the photos. Anything derived from your face is used
only for this check within your own account, never to identify you anywhere
else. No photos, no
check: you do not have to
share a photo in order to talk to the matchmaker, but appearance is an important
part of the process and we cannot make offers to a user who has no photos.
**d. Safety and harm prevention.** Detecting abusive behaviour, harassment,
fraud or risk; handling reports, including review of a reported conversation;
and warning, suspending or blocking users. Basis: the legitimate interest of
our users and ourselves in a safe service, and duties that apply to us by law.
**e. Support and troubleshooting.** Answering your enquiries and diagnosing
faults. For this, an authorised staff member may open and read a conversation.
**f. Operations, security and accounting.** Running the systems, backups,
information security, preventing misuse, tracking operating costs, and managing
subscriptions.
**g. Notifications.** Service messages and reminders (for example "you have a
pending offer") pushed to the app. Marketing mail - if there ever is any - will
go only to people who agreed to it in advance and will always carry a simple way
to unsubscribe.
**What we will not do with it, in the future either:** we will not sell it, rent
it, or share it with third parties for their own purposes. That is a
commitment, not a policy subject to change.
**What we do not do today:** we do not use your conversations to train or
evaluate models or the service. If we want to do so in the future, we will ask
for separate, explicit consent - consent you gave for one purpose is not used by
us for another.
## 5. The matchmaker is an AI, and staff can read
The matchmaker you talk to is software. It is not a person, even when it sounds
like one, and it can be wrong. None of our staff write in its name or in your
name in conversations with real users.
At the same time - and this matters - **authorised staff at Tandu can read
the content of your conversations with the matchmaker**, for safety, support,
and troubleshooting. A matchmaking service cannot operate otherwise.
Conversations between you and a match are different: staff interfaces do not
expose their content, and they are opened for review only when one of you
reports the other, or where the law requires it. In both cases what protects
you is not a promise but a mechanism: access is
personal and named (there are no shared logins), it is written to an audit log -
who, which conversation, when - and it is governed by a binding data-handling
procedure, which everyone exposed to the data commits to and is retrained on
periodically.
## 6. Who receives the information
Information stays inside our cloud environment, except for the categories of
recipient set out here. **This is an exhaustive list - there is nothing beside
it.** Each of them is a service provider acting for us and on our instructions,
under a contract that requires it to secure the information and not to use it
for its own purposes:
- **The cloud infrastructure provider** the service runs on: servers, database,
and photo storage. Receives all classes of data - stored, not viewed.
- **The sign-in account provider you chose** (Google or Apple, as stated in
section 3) **and the identity service** that runs sign-in and phone
verification for us, including sending the SMS with the code. They receive an
account identifier, email address and phone number. The sign-in account
provider acts as an independent controller for its own sign-in service.
- **Language-model providers** - conversation content and photos are sent to
them in order to generate the matchmaker's reply and the profile. Under the
business terms we agreed with them, these providers **do not use the content
to train their models**; content may be retained on their side for a short
period for abuse monitoring.
- **The notification delivery service** to your device. Receives a device
identifier and the content of the notification.
- **Technical monitoring and error-reporting tools.** They receive data about
how the system runs - timings, errors, model and cost - and are configured not
to collect conversation content or identifying details.
- **The operational alerting tool for the team.** Receives identifiers and
numbers only, not content.
- **The app stores and the service that manages subscriptions for us.** They
receive subscription status; payment details stay with the store and never
reach us at all.
We will also disclose information where we are required to by law or court
order - including where the law obliges us to report on our own initiative, as
with suspected harm to a minor or knowledge of a serious offence about to be
committed - where it is needed to protect against a real danger to a person's
life or safety, or to protect our rights in legal proceedings. If the company is sold or
merged, information may pass to the acquirer - subject to their continuing to
handle it under this policy, and with advance notice.
## 7. Where the information is kept
Our servers and database are hosted on a public cloud, in a region in the
western United States, and the language-model providers likewise operate in the
United States. In other words: **your information is stored and processed
outside Israel.** The transfer is to providers contractually bound to us to
safeguard the information and process it only on our instructions, and is
permitted under the Privacy Protection Regulations (Transfer of Data to
Databases Abroad).
## 8. How long we keep it
- **Account details, conversations, photos, and information derived from them** -
for as long as the account exists. On a deletion request: a further 30 days (a
window in which you can change your mind), and then everything is deleted.
- **The consent record** - kept after account deletion, without identifying
details, because it is the proof that consent was given and exactly what was
shown to you.
- **Operational and audit records** (who accessed what, operating costs, system
events) - kept long-term, content-free, and detached from you on deletion.
- **Error logs and telemetry** - 30 to 90 days.
- **Backups** - point-in-time recovery up to 7 days, retained backups up to 14
days, previous file versions 30 days. Deleted data ages out of backups within
these windows, and a restore re-applies any pending deletions.
- **Safety-flagged material** - see section 10.
## 9. Your rights
- **To review your information** (section 13 of the Law) - including the profile
and summaries built about you. What was derived from the conversation and not
stated by you explicitly is information about you too. We do not keep a secret
file you cannot see.
- **To request correction** of information that is wrong, incomplete, or out of
date (section 14 of the Law). What is derived from a conversation is not always
a fact: we do not undertake to change every item, but you may attach your own
comment, and it will be kept alongside it.
- **To delete your account** and your information - see section 10.
- **To withdraw consent** at any time. Withdrawing consent to processing for
matchmaking stops the processing that relies on it, and since that is the core
of the service, it closes your account and leads to its deletion. Withdrawal
operates forward and does not affect the lawfulness of what was done before it.
- **To object** to particular processing or to ask that it be restricted.
- **To complain** to the Privacy Protection Authority at the Ministry of
Justice, if you believe we have infringed your rights.
How to exercise them: write to **privacy@tandu.me**, or tell the matchmaker in
conversation - it will pass it on. We respond within 30 days. There is no
charge. To protect you, we will verify that the requester is the account holder
(usually: a request from the account's email address).
## 10. Account deletion - exactly what happens
You can delete your account from within the app, or ask us to. The request is
recorded immediately, and deletion is carried out after **30 days** - a window
in which you can cancel the request and come back.
**What is deleted:** your name, email, phone, date of birth, area of residence
and location, and every other identifying detail; all your conversations; the
photos themselves and what we derived from them; the profile and
summaries built about you; and the account at the sign-in provider
(Google/Apple), so that the phone number and email are released.
**What remains, and why:**
- **An identity-free row** representing the account. It contains no personal
detail at all, and remains so that other records pointing to it do not break.
- **Messages already sent to another person** remain with them, without your
name - they are that person's correspondence too. We do not delete one
person's history because someone else left. By contrast, anything that is a
record **about you** - profile facts and summaries - is deleted even where it
sits on the other side.
- **The match record itself** (that there was a match, when, and what came of
it) remains without content and without identifying details, so that the other
person's history stays intact.
- **Audit and cost records**, detached from you and without content.
- **The consent record**, as stated in section 8.
**Safety-flagged material - the exception.** If your conversation contains
material flagged with us as suspected harassment, harm or an offence, we will
keep **that material alone for 12 months** from the deletion, so that deleting an
account cannot be used to destroy evidence against a harasser. If a complaint or
proceeding is open at that time, the material is kept until it concludes. During
that period the material is out of circulation: it is not visible to other users
and does not appear in ordinary staff interfaces, only through a separate,
logged access path. If this applies to you, we will tell you so at the time of
the request, explain what is being kept and why, and tell you that you may
complain to the Privacy Protection Authority. The rest of your information is
deleted regardless, on the ordinary schedule.
**If your account was blocked - the exclusion list.** If we blocked your
account for the safety of other users, we keep, even after deletion, an
irreversible fingerprint (a one-way hash) of your verified phone number, so
that the same number cannot simply open a new account. The fingerprint cannot
be turned back into the number, it is not linked to your name or any other
identifying detail, and it serves exactly one purpose: recognising a blocked
number at registration.
## 11. How the information is protected
- The application's access to the database is limited and defined; human access
is personal, named and read-only, controlled by permissions and logged.
- Information is encrypted in transit and at rest.
- Production data is never downloaded to personal computers; development uses
synthetic data.
- Production and test environments are fully separated.
- Monitoring tools are configured not to collect content or identifying details.
- Anyone exposed to the data is bound by a written data-handling procedure, takes
periodic refresher training on it, and is under a confidentiality obligation.
- We run backups and restore drills, periodic risk surveys and penetration
tests, and review access logs at set intervals.
No system is immune. If a serious security incident affecting your information
occurs, we act under an internal procedure: contain, assess, notify the Privacy
Protection Authority as the law requires, and notify you where notification is
required or is the right thing to do.
## 12. Age
The service is for people aged 18 and over only. At the start of the
conversation we ask for your date of birth; if someone states an age under 18,
their account is deleted immediately and we learn nothing about them. The
statement is not the only check: the age estimate from the photos may point to a
gap between what was stated and what is visible, and we then look into it. If we
discover an account was opened by a minor, we delete it.
## 13. Automated decisions
Matches are selected by an automated process that matches candidates against the
profile built from your conversations. These decisions have no legal or
similarly significant effect on your rights - they are introductions. You may
always contact us, ask for an explanation, and ask for human review.
The safety checks too - the age and gender estimate from the photos, the
comparison between the photos, and location consistency - are not decisive on
their own. They flag an account, and blocking or deletion is a person's
decision, which you can appeal with us.
## 14. Changes to this policy
Every change is published as a new version with an effective date, and the
version you consented to is preserved. A material change - especially one that
widens the purposes of use - will not be applied to you on the strength of old
consent: we will present it and ask for consent again. Previous versions are
available on request.
## 15. Governing law and binding text
This policy is governed by the laws of the State of Israel, and the competent
courts of the Tel Aviv-Jaffa district have jurisdiction. **The Hebrew document is
the binding text.** This English translation is for convenience only; in case of
conflict, the Hebrew prevails.
**Contact:** privacy@tandu.me · Tandu Me LTD, Klil HaHoresh 274, Nes Harim
9988500.
v2 · 2026-08-19 · source