# Tandu Privacy Policy **Version 2 - effective 19 August 2026.** *This is a courtesy translation. The Hebrew version is the binding text; where the two differ, the Hebrew governs.* Tandu Me LTD ("Tandu", "we") is an Israeli company operating an AI-based matchmaking service. This document explains what information we collect about you, what we do with it, who receives it, how long we keep it, and what you can do about it. We wrote it to be understood, not to be long. Information about a person's romantic life is especially sensitive under Israel's Privacy Protection Law. That is exactly the kind of information this service deals in, which is why we ask for your explicit, separate consent before we learn anything about you. ## In short - We collect what you tell the matchmaker in conversation, the photos you share, and basic account details: name, email address, date of birth, phone number and area of residence. - **Several things here are safety measures.** A verified phone number makes sure that one real person stands behind each account; approximate, city-level location makes sure the offers you get are within a distance you can actually act on, and catches an account that is not where it claims to be; and we examine the photos - estimating age and gender from them, and comparing them to one another to confirm they are all of the same person. The comparison is automated: we use technological means to tell whether the same person appears in the photos. Anything derived from the photos for this check - biometric data included - is used only for this check within your own account, is never compared against any external database, and is kept on the photo's own record and deleted with it. Your number and your location are not shown to any other user, and a machine's estimate never blocks you without a person having looked. - The matchmaker is **an AI**, not a person. It reads the conversation and builds a profile from it, in order to find you the right person. - Your conversation content is sent to an external language-model provider in the United States, which generates the reply. These providers do not use your content to train their models. - **Authorised staff at Tandu can read your conversations with the matchmaker** - for safety, support, and troubleshooting. A conversation between you and a match is opened for review only if one of you reports the other. Every such access is logged, and anyone with access is bound by a written internal procedure. - We **do not sell your information and do not share it for advertising** - not today and not in the future. - We **do not use your conversations to train or evaluate models**. If we want to do so in the future, we will ask you for separate, explicit consent, and you will be free to refuse without it affecting the service. - You can at any time ask to see your information, correct it, delete your account, or withdraw your consent. - For anything privacy-related: **privacy@tandu.me**. ## 1. Who we are Tandu Me LTD, a company registered in Israel, Klil HaHoresh 274, Nes Harim 9988500. The company is the database owner and is responsible for the information. Privacy enquiries go to **privacy@tandu.me**. We have not appointed a statutory Privacy Protection Officer, because we are not among the bodies required to appoint one; the duties themselves rest with a defined role here. ## 2. Giving us information is voluntary You are under no legal obligation to give us information. But the service is built on what you tell the matchmaker: without consent to process your information for matchmaking we cannot operate the service for you, and without a verified phone number and without access to your approximate location we cannot present you with a match offer. ## 3. What we collect **Account details.** You sign in with an existing Google or Apple account. From that we receive an account identifier and an email address. We also store: a name or nickname you choose for us to use, full date of birth, phone number and when it was verified, the area of residence you tell us, time zone, and device identifiers for notifications. **We do not ask for or store an identity document.** If we conclude that verification against an identity document is necessary for users' safety, we will not start doing it quietly: we will publish a new version of this policy setting out exactly what is collected, who sees it and how long it is kept, and ask for your consent again. **Area of residence and device location.** The area you live in - a city or a region - is something you tell the matchmaker in conversation, and we keep it in order to suggest people who live within a distance you can act on. In addition, the app asks for access to your device location at an approximate level, and we compare it against the area you gave us - a consistency check that helps identify accounts that are not who they present themselves to be. **This permission is required in order to use the service:** without it we cannot offer you matches, and if you revoke it in your device settings, offers stop until you restore it. We ask for **approximate location only, at city level** - not precise location. We keep only your current location and not a movement history, and we do not show it to any other user. **Conversations with the matchmaker.** Everything written in the conversation is stored. That includes anything you choose to share about your relationships, preferences, family status, religion and worldview, and anything else that comes up. **Photos.** Photos you upload in conversation, including photos of yourself. From photos in which a face is visible we derive two things for safety purposes (see section 4(c)): an estimate of age and of gender, and a comparison of your photos against one another - to confirm that they all show the same person. The comparison is automated: we use technological means (section 6) to tell whether the same person appears in the photos and to estimate age from them. Anything derived from your photos for this check - biometric data included - is used solely for this purpose within your own account: it is not used to identify you anywhere else, it is not compared against any external face database, and we pass it to no one. It is held on the photo's own record and deleted when the photo is deleted. The check's result in words - an age range, an assessment of gender, whether the photos appear to be of one person, and a short note - is kept the same way, and shown to you on request. **Conversations with a match.** When you begin chatting in the app with someone you have been matched with, that conversation is stored with us. The matchmaker itself does not receive its contents - it sees only metadata about the conversation (for example that it happened, and at what pace). We do not read these conversations in the ordinary course, and no automated screening runs on them. What opens such a conversation to review is a report: if either of you reports the other, the conversation between you may be reviewed by our safety team - and the report screen says so at the moment of reporting. **Reports.** If you report another user - or another user reports you - we keep the report: who reported whom, the reason chosen, anything written in it, and what we decided on it. A report is information about both sides, and it is kept under the safety exception in section 10. **Information derived from all of the above.** From conversations and photos we build your profile: profile facts (for example "looking for something serious", "traditionally observant"), conversation summaries, and questions and answers relayed between you and a match. We hold ourselves to a simple rule: we do not keep information about you that we would not be willing to show you. **An impression from your photos.** From your photos we form an overall impression of how you come across in them. The impression stays private, it is used to suggest matches, and you receive it together with advice on how to present yourself best in your photos. **The consent record.** For every consent you give we keep a record: which purpose, exactly which text was shown to you, in which language, exactly what you replied, and when. **Operational and control records.** System and error logs, performance metrics, a record of every language-model call (model, token counts, cost - no content), and audit records showing which staff member accessed what and when. These records contain identifiers and numbers only, never conversation content. **Paid subscription information.** Tandu Plus is purchased through the app store (Apple or Google). **We never see or store payment details.** What reaches us is subscription status and validity. **What we don't do.** The app contains no advertising trackers, and we pass nothing to advertisers, data brokers, or social networks. ## 4. Why we use the information, and on what basis **a. Operating the service and matchmaking.** Running the conversation with the matchmaker, building the profile, finding suitable candidates - including matching by area of residence, so that the offers you get are within a distance you can act on - presenting offers, relaying questions and answers between you and a match, and running the conversation between the two sides. Basis: performance of our agreement - this is the service you asked for. **b. Processing sensitive information.** Learning your romantic and sexual preferences and orientation, your family status, your religion and worldview, and building your profile on that basis - for matchmaking. This includes the photos you share, what is derived from them for the check, and the check's result. Basis: **your explicit consent**, which we request at the start of the conversation - and which says explicitly that we examine the photos. **c. Identity verification - a safety measure.** A verified phone number helps us keep one real person behind each account. It prevents duplicate accounts and impersonation, and it is what allows us to block someone who behaved badly without their immediately opening a new account under another name. That is why phone verification is a condition for receiving a match offer: we want you to know that the person facing you passed the same check. It is not a condition for talking to the matchmaker itself, and we do not show your number to any other user. Alongside it there are three further signals serving the same purpose: the comparison between your device location and the area you gave us, the estimate of age and gender derived from the photos, and the comparison of your photos against one another. They are there to identify an account that is not who it presents itself to be - a minor posing as an adult, or an account whose photos are not of one person. **An estimate from a photo can be wrong, and so it is never decisive on its own:** it flags an account for review, and the decision to block or delete is a person's. If you were flagged by mistake, a single message to privacy@tandu.me is enough for us to look again, and what you tell us about yourself outweighs what the machine guessed. **The phone and the location** rest on performance of our agreement - a service that offers you people in your area cannot work without knowing where you are - and alongside it on the legitimate interest of all users in a service that can be relied on. **Examining the photos** may involve biometric information: its basis is your explicit consent under section 4(b), and the wording in which we ask for it says explicitly that we examine the photos. Anything derived from your face is used only for this check within your own account, never to identify you anywhere else. No photos, no check: you do not have to share a photo in order to talk to the matchmaker, but appearance is an important part of the process and we cannot make offers to a user who has no photos. **d. Safety and harm prevention.** Detecting abusive behaviour, harassment, fraud or risk; handling reports, including review of a reported conversation; and warning, suspending or blocking users. Basis: the legitimate interest of our users and ourselves in a safe service, and duties that apply to us by law. **e. Support and troubleshooting.** Answering your enquiries and diagnosing faults. For this, an authorised staff member may open and read a conversation. **f. Operations, security and accounting.** Running the systems, backups, information security, preventing misuse, tracking operating costs, and managing subscriptions. **g. Notifications.** Service messages and reminders (for example "you have a pending offer") pushed to the app. Marketing mail - if there ever is any - will go only to people who agreed to it in advance and will always carry a simple way to unsubscribe. **What we will not do with it, in the future either:** we will not sell it, rent it, or share it with third parties for their own purposes. That is a commitment, not a policy subject to change. **What we do not do today:** we do not use your conversations to train or evaluate models or the service. If we want to do so in the future, we will ask for separate, explicit consent - consent you gave for one purpose is not used by us for another. ## 5. The matchmaker is an AI, and staff can read The matchmaker you talk to is software. It is not a person, even when it sounds like one, and it can be wrong. None of our staff write in its name or in your name in conversations with real users. At the same time - and this matters - **authorised staff at Tandu can read the content of your conversations with the matchmaker**, for safety, support, and troubleshooting. A matchmaking service cannot operate otherwise. Conversations between you and a match are different: staff interfaces do not expose their content, and they are opened for review only when one of you reports the other, or where the law requires it. In both cases what protects you is not a promise but a mechanism: access is personal and named (there are no shared logins), it is written to an audit log - who, which conversation, when - and it is governed by a binding data-handling procedure, which everyone exposed to the data commits to and is retrained on periodically. ## 6. Who receives the information Information stays inside our cloud environment, except for the categories of recipient set out here. **This is an exhaustive list - there is nothing beside it.** Each of them is a service provider acting for us and on our instructions, under a contract that requires it to secure the information and not to use it for its own purposes: - **The cloud infrastructure provider** the service runs on: servers, database, and photo storage. Receives all classes of data - stored, not viewed. - **The sign-in account provider you chose** (Google or Apple, as stated in section 3) **and the identity service** that runs sign-in and phone verification for us, including sending the SMS with the code. They receive an account identifier, email address and phone number. The sign-in account provider acts as an independent controller for its own sign-in service. - **Language-model providers** - conversation content and photos are sent to them in order to generate the matchmaker's reply and the profile. Under the business terms we agreed with them, these providers **do not use the content to train their models**; content may be retained on their side for a short period for abuse monitoring. - **The notification delivery service** to your device. Receives a device identifier and the content of the notification. - **Technical monitoring and error-reporting tools.** They receive data about how the system runs - timings, errors, model and cost - and are configured not to collect conversation content or identifying details. - **The operational alerting tool for the team.** Receives identifiers and numbers only, not content. - **The app stores and the service that manages subscriptions for us.** They receive subscription status; payment details stay with the store and never reach us at all. We will also disclose information where we are required to by law or court order - including where the law obliges us to report on our own initiative, as with suspected harm to a minor or knowledge of a serious offence about to be committed - where it is needed to protect against a real danger to a person's life or safety, or to protect our rights in legal proceedings. If the company is sold or merged, information may pass to the acquirer - subject to their continuing to handle it under this policy, and with advance notice. ## 7. Where the information is kept Our servers and database are hosted on a public cloud, in a region in the western United States, and the language-model providers likewise operate in the United States. In other words: **your information is stored and processed outside Israel.** The transfer is to providers contractually bound to us to safeguard the information and process it only on our instructions, and is permitted under the Privacy Protection Regulations (Transfer of Data to Databases Abroad). ## 8. How long we keep it - **Account details, conversations, photos, and information derived from them** - for as long as the account exists. On a deletion request: a further 30 days (a window in which you can change your mind), and then everything is deleted. - **The consent record** - kept after account deletion, without identifying details, because it is the proof that consent was given and exactly what was shown to you. - **Operational and audit records** (who accessed what, operating costs, system events) - kept long-term, content-free, and detached from you on deletion. - **Error logs and telemetry** - 30 to 90 days. - **Backups** - point-in-time recovery up to 7 days, retained backups up to 14 days, previous file versions 30 days. Deleted data ages out of backups within these windows, and a restore re-applies any pending deletions. - **Safety-flagged material** - see section 10. ## 9. Your rights - **To review your information** (section 13 of the Law) - including the profile and summaries built about you. What was derived from the conversation and not stated by you explicitly is information about you too. We do not keep a secret file you cannot see. - **To request correction** of information that is wrong, incomplete, or out of date (section 14 of the Law). What is derived from a conversation is not always a fact: we do not undertake to change every item, but you may attach your own comment, and it will be kept alongside it. - **To delete your account** and your information - see section 10. - **To withdraw consent** at any time. Withdrawing consent to processing for matchmaking stops the processing that relies on it, and since that is the core of the service, it closes your account and leads to its deletion. Withdrawal operates forward and does not affect the lawfulness of what was done before it. - **To object** to particular processing or to ask that it be restricted. - **To complain** to the Privacy Protection Authority at the Ministry of Justice, if you believe we have infringed your rights. How to exercise them: write to **privacy@tandu.me**, or tell the matchmaker in conversation - it will pass it on. We respond within 30 days. There is no charge. To protect you, we will verify that the requester is the account holder (usually: a request from the account's email address). ## 10. Account deletion - exactly what happens You can delete your account from within the app, or ask us to. The request is recorded immediately, and deletion is carried out after **30 days** - a window in which you can cancel the request and come back. **What is deleted:** your name, email, phone, date of birth, area of residence and location, and every other identifying detail; all your conversations; the photos themselves and what we derived from them; the profile and summaries built about you; and the account at the sign-in provider (Google/Apple), so that the phone number and email are released. **What remains, and why:** - **An identity-free row** representing the account. It contains no personal detail at all, and remains so that other records pointing to it do not break. - **Messages already sent to another person** remain with them, without your name - they are that person's correspondence too. We do not delete one person's history because someone else left. By contrast, anything that is a record **about you** - profile facts and summaries - is deleted even where it sits on the other side. - **The match record itself** (that there was a match, when, and what came of it) remains without content and without identifying details, so that the other person's history stays intact. - **Audit and cost records**, detached from you and without content. - **The consent record**, as stated in section 8. **Safety-flagged material - the exception.** If your conversation contains material flagged with us as suspected harassment, harm or an offence, we will keep **that material alone for 12 months** from the deletion, so that deleting an account cannot be used to destroy evidence against a harasser. If a complaint or proceeding is open at that time, the material is kept until it concludes. During that period the material is out of circulation: it is not visible to other users and does not appear in ordinary staff interfaces, only through a separate, logged access path. If this applies to you, we will tell you so at the time of the request, explain what is being kept and why, and tell you that you may complain to the Privacy Protection Authority. The rest of your information is deleted regardless, on the ordinary schedule. **If your account was blocked - the exclusion list.** If we blocked your account for the safety of other users, we keep, even after deletion, an irreversible fingerprint (a one-way hash) of your verified phone number, so that the same number cannot simply open a new account. The fingerprint cannot be turned back into the number, it is not linked to your name or any other identifying detail, and it serves exactly one purpose: recognising a blocked number at registration. ## 11. How the information is protected - The application's access to the database is limited and defined; human access is personal, named and read-only, controlled by permissions and logged. - Information is encrypted in transit and at rest. - Production data is never downloaded to personal computers; development uses synthetic data. - Production and test environments are fully separated. - Monitoring tools are configured not to collect content or identifying details. - Anyone exposed to the data is bound by a written data-handling procedure, takes periodic refresher training on it, and is under a confidentiality obligation. - We run backups and restore drills, periodic risk surveys and penetration tests, and review access logs at set intervals. No system is immune. If a serious security incident affecting your information occurs, we act under an internal procedure: contain, assess, notify the Privacy Protection Authority as the law requires, and notify you where notification is required or is the right thing to do. ## 12. Age The service is for people aged 18 and over only. At the start of the conversation we ask for your date of birth; if someone states an age under 18, their account is deleted immediately and we learn nothing about them. The statement is not the only check: the age estimate from the photos may point to a gap between what was stated and what is visible, and we then look into it. If we discover an account was opened by a minor, we delete it. ## 13. Automated decisions Matches are selected by an automated process that matches candidates against the profile built from your conversations. These decisions have no legal or similarly significant effect on your rights - they are introductions. You may always contact us, ask for an explanation, and ask for human review. The safety checks too - the age and gender estimate from the photos, the comparison between the photos, and location consistency - are not decisive on their own. They flag an account, and blocking or deletion is a person's decision, which you can appeal with us. ## 14. Changes to this policy Every change is published as a new version with an effective date, and the version you consented to is preserved. A material change - especially one that widens the purposes of use - will not be applied to you on the strength of old consent: we will present it and ask for consent again. Previous versions are available on request. ## 15. Governing law and binding text This policy is governed by the laws of the State of Israel, and the competent courts of the Tel Aviv-Jaffa district have jurisdiction. **The Hebrew document is the binding text.** This English translation is for convenience only; in case of conflict, the Hebrew prevails. **Contact:** privacy@tandu.me ยท Tandu Me LTD, Klil HaHoresh 274, Nes Harim 9988500.