Cadence logo
Cadence

Privacy Policy

This explains what Cadence collects, why, and the rights you have over it. Effective from account creation.

Last updated: 27 August 2026

Who we are

Cadence is operated from Ireland. For any privacy question or to exercise the rights below, contact cadencedating@gmail.com or use Contact Support in Settings. We are the data controller for the personal data described here.

What we collect

Account data: email address and password (hashed by our authentication provider — we never see it in plain text), and date of birth (used once to confirm you are 18+; we store the resulting age, not a birth date, on your visible profile). Profile data: name, bio, running stats (pace, personal bests, favourite distance, running club), photos you upload, and your gender and match preferences. Location data: your device GPS coordinates, used only to compute distance to other runners. Other users only ever see an approximate place name (e.g. "Dublin"), never coordinates — see "Location" below for detail on how this is enforced. Content: messages you send to matches, reports you file, and support requests. Usage & device data: push notification token, app version, device platform, and approximate timestamps of activity (last seen). We also collect in-app usage analytics (screens viewed and feature interactions, tied to a randomly generated device ID, not your name or email) and crash/error reports (device model, OS version, and the app's state at the time of an error) to help us understand how Cadence is used and fix problems. Payment data: if you subscribe to Pro, our payment processor (Stripe, or the App Store/Play Store once native billing is live) handles your card details directly — we only ever receive a customer/subscription reference ID, never your card number. Verification data: if you complete selfie verification, your selfie is compared against your profile photo by our verification provider and is not retained by Cadence after the check completes. Because this involves facial comparison, we ask for your explicit, separate consent immediately before each verification attempt — agreeing to this Privacy Policy alone does not cover it.

Why we process it (legal basis)

Contract: account creation, matching, messaging, and Pro billing are necessary to provide the service you signed up for. Consent: showing your profile, photos, and approximate location to other users is consent-based — you can withdraw it at any time by deleting your account, which removes all of it. Legitimate interest: fraud prevention, abuse/moderation, and keeping the service secure. Legal obligation: responding to lawful requests from authorities, and retaining minimal records where required by law (e.g. tax records for payments).

Location

Your exact coordinates are stored so distance-based matching works, but they are never sent to another user's device — the database enforces this at the row level, not just in the app's UI: other users can only read a restricted view of your profile that excludes coordinates entirely. Distance calculations happen server-side; only the resulting approximate place name is shared.

Who we share it with

We use a small number of processors, each under a data processing agreement: • Supabase (Ireland/EU-hosted) — database, authentication, file storage, and realtime messaging. • Stripe / Apple / Google — payment processing for Pro subscriptions. • AWS Rekognition — selfie verification comparison, at time of verification only. • Expo — push notification delivery (receives only your device push token, not profile content). • Sentry (EU-hosted) — crash and error reporting. • PostHog (EU-hosted) — in-app usage analytics. We do not sell your personal data, and we do not share it with data brokers or advertisers.

International transfers

Our processors may transfer data outside the EEA (for example, AWS Rekognition and Expo's push infrastructure run partly in the US). Where this happens, it is covered by Standard Contractual Clauses or an equivalent safeguard required under GDPR.

How long we keep it

Your account data is kept for as long as your account is active. Messages and matches are kept until you delete the match, unmatch, or delete your account. Deleting your account permanently removes your profile, photos, messages, matches, swipes, and blocks within our systems — this cannot be undone. Support requests are retained for up to 2 years for quality and safety review. Selfie verification images are not retained after the check completes.

Your rights

Under GDPR you can: access the personal data we hold on you (Export my data, in Settings), correct it (edit your profile directly), delete it (Delete my account, in Settings — irreversible), restrict or object to certain processing, and request data portability. To exercise any right not available directly in the app, contact cadencedating@gmail.com. You also have the right to complain to the Irish Data Protection Commission (dataprotection.ie) if you believe we have mishandled your data.

Children

Cadence is strictly for adults 18 and older. We do not knowingly collect data from anyone under 18. If we become aware that an underage person has created an account, we will delete it and the data associated with it. See our Child-Safety Standards for more detail.

Data breach notification

In the event of a personal data breach likely to result in a risk to your rights, we will notify the Data Protection Commission within 72 hours of becoming aware of it, and will notify affected users directly where the breach is likely to result in a high risk to them.

Changes to this policy

If we make a material change to this policy, we will notify you in-app before it takes effect.