Skip to content
? WhyNot
How it works Meet Adrian About FAQ Get the app
How it works Meet Adrian About FAQ Get the app
  1. Home ›
  2. Privacy Policy

Legal

Privacy Policy

Last updated: August 10, 2026

This Privacy Policy describes how WhyNot ("WhyNot", "we", "us", or "our") collects, uses, and shares your personal information when you use our mobile application. By creating an account or using the app, you agree to the practices described below.

WhyNot was previously in testing under the working name "Thrive Dating" — this policy covers the same service under its current name.

1. Who We Are

WhyNot is an independently operated dating application, operated by Raymond Stump in the United States, who acts as the data controller for the personal information described in this policy. For any privacy-related questions or requests, contact us at stump865+privacypolicy@gmail.com.

2. Information We Collect

2.1 Account & profile information

  • Email address and password (stored and authenticated through Supabase)
  • Profile details you provide: name, age, gender, pronouns, bio, preferences, and interests
  • Sensitive information: your sexual orientation and who you are looking to meet. This is "special category" / "sensitive personal information" under laws such as the GDPR and the CCPA. We collect it only with your explicit, affirmative consent given at the point of collection, use it solely to suggest compatible matches, and never sell it or use it for advertising. See section 4a below.
  • Profile photos you upload
  • Onboarding answers you share with our AI matchmaker ("Adrian") during account setup

2.2 Location data

  • Your approximate and precise location when the app is open, and — if you grant permission — in the background
  • Location is used to suggest nearby matches and recommend local date spots. You can disable location access at any time in your device settings
  • We store only your most recent reported location (and when it was updated) — we do not keep a running history of your movements

2.3 Microphone and audio

  • When you use voice chat with our AI matchmaker ("Adrian"), we capture your microphone audio and send it to our backend for processing and real-time AI conversation
  • Audio is processed by OpenAI under their Realtime API and is not retained in raw form on our servers beyond what is necessary for the active session
  • A text transcript of what you and Adrian say may be generated during the conversation; where it forms part of your conversation history with Adrian, it is stored like any other message (see section 2.5). The raw audio itself is not stored

2.4 Camera and photo library

  • When you upload a profile photo, the app requests access to your camera or photo library to select an image. Only images you explicitly select are uploaded

2.5 Messages and interactions

  • Messages you send to matched users
  • Messages you exchange with our AI matchmaker ("Adrian")
  • Matches, likes, blocks, reports, and date recommendations

2.6 Device & usage information

  • Push notification token (if you opt in to notifications)
  • Device type, operating system version, and app version
  • Crash and error diagnostics (via Sentry)
  • Sign-in records: each time you sign in we record the device type, operating system and app version, the IP address the sign-in came from, and an approximate location (city/region/country) derived from that IP address. This is not GPS data and can name a nearby city rather than yours. You can review this history in the app under Account settings → Devices & sign-in activity
  • Product-analytics events — screens viewed and in-app actions taken, keyed to your account identifier (via PostHog). These record which features you use, not the content of your messages or profile text
  • An advertising identifier (Apple IDFA / Google Advertising ID) and ad-interaction data, used to serve ads through our advertising partner. This is collected and shared only after you make a tracking choice (see sections 4 and 6); if you decline tracking, no advertising identifier is collected or shared

3. How We Use Your Information

  • To create and maintain your account
  • To match you with other users based on profile data, preferences, and location
  • To power our AI matchmaker ("Adrian"), which helps with onboarding, conversation, and date recommendations
  • To generate personalized date spot suggestions near you
  • To send you push notifications you have opted in to
  • To keep photos and messages safe by screening uploaded photos and filtering prohibited content
  • To enforce our community standards (e.g., acting on reports, blocking abusive users)
  • To understand which features are used, diagnose crashes, and improve the app
  • To display advertising, which is how the app is supported

4. Third-Party Services (Subprocessors)

We share the minimum information required for these services to function. The table below is kept in step with our internal subprocessor register; each listed provider processes your data under a data-processing agreement.

  • Supabase — authentication, database, and file storage. Holds your profile, messages, photos, and location. Privacy policy.
  • OpenAI — powers Adrian's chat and voice conversations, profile-description generation, and parts of the compatibility and date-recommendation logic. Your conversation text, profile text, and (for voice chat) audio are sent to OpenAI's API for processing. OpenAI does not use data submitted through its API to train its models, and no advertising identifier or persistent WhyNot account identifier is sent. Privacy policy.
  • Google (Gemini) — powers additional Adrian replies, date-recommendation, and profile-scoring features. Relevant profile and conversation text is sent to Google's AI API for processing; no advertising identifier or persistent WhyNot account identifier is sent. Privacy policy.
  • Anthropic (Claude) — used to generate certain AI-written profile responses. Relevant profile and conversation text is sent to Anthropic's API for processing; no advertising identifier or persistent WhyNot account identifier is sent. Privacy policy.
  • Sightengine — automated moderation of the profile photos you upload, to detect nudity and prohibited content before a photo becomes visible to others. Photo image data is sent for a moderation verdict; no WhyNot account identifier is sent. Privacy policy.
  • AppLovin (MAX) — our advertising partner, used to serve ads in the app. Receives your advertising identifier (Apple IDFA / Google Advertising ID) and ad-interaction data, and only after you have made a tracking choice (Apple App Tracking Transparency on iOS, and a consent prompt where the GDPR applies). If you decline tracking, no advertising identifier is shared with AppLovin. Privacy policy.
  • PostHog — product analytics. Receives in-app events (screens viewed, actions taken) keyed to your account identifier so we can understand feature usage and retention. It does not receive your message content, profile free-text, or advertising identifier. Privacy policy.
  • Sentry — crash and error diagnostics. Receives technical crash data and your account identifier; it is configured not to receive message content, names, or authentication tokens. Privacy policy.
  • Resend — sends transactional emails (for example, report confirmations, data exports, and account-deletion notices). Receives the recipient email address. Privacy policy.
  • Apple Push Notification Service / Google Firebase Cloud Messaging (via Expo) — used to deliver push notifications if you have opted in. Receives a push-delivery token, not your account content.
  • ipinfo.io — turns the IP address recorded when you sign in into an approximate city, so your sign-in activity is readable ("Philadelphia, PA" rather than a number). Receives the IP address only — no name, account identifier, or profile data. Privacy policy.
  • Our backend host — runs the server that brokers requests between the app and the services above. Map tiles are served by OpenFreeMap (OpenStreetMap data); date-spot venue data is served from our own curated database, and geocoding uses OpenStreetMap's Nominatim service.

We do not sell your personal information. We share an advertising identifier with our advertising partner (AppLovin) as described above so that ads can be shown; you can stop this by declining tracking, changing your choice later in Account settings → Privacy & AI, or adjusting your device settings. Under the California Privacy Rights Act (CPRA), passing an advertising identifier to an advertising partner may be considered "sharing" for cross-context behavioral advertising. Declining the tracking prompt (or changing your choice later in Account settings → Privacy & AI, or in your device settings) is how you opt out of this sharing; if you decline, no advertising identifier is shared. We do not share your sensitive information (section 4a), messages, or profile free-text with advertisers.

4a. Sensitive information & your consent

Your sexual orientation and who you are looking to meet are treated as sensitive/special-category data. During sign-up we show a short notice at the point we collect these fields and require your affirmative consent before your profile can be created. We use this information only to suggest compatible matches. We never sell it, never use it for advertising, and never share it with the analytics, advertising, or AI providers listed above beyond what is strictly necessary to show you relevant matches.

Because matching people according to who they want to meet is the core of the service, we cannot provide WhyNot without processing this information — there is no way to use the app while opting out of it. If you no longer want us to process it, you can stop using the service and delete your account (section 6), which removes this data along with the rest of your profile. Consent choices that are separable from the core service — AI features, ads, and tracking — can each be withdrawn individually in-app at any time, as easily as they were given (section 6).

5. Data Retention

  • Your profile, photos, messages, matches, and safety records (reports and blocks) are retained for as long as your account is active, and are removed when you delete your account (see section 6)
  • Operational and analytics data is kept only for a limited window and then automatically pruned — for example, profile-view history for about 12 months, advertising events for about 13 months, in-app notifications for about 6 months, and AI-usage accounting for about 24 months
  • Sign-in records (section 2.6) are kept for 90 days after the session they describe has ended, so you can review recent activity on your account, and then deleted
  • When you delete your account, we remove your profile, photos, and messages from our active systems and propagate the deletion to the subprocessors that hold account-linked data (for example, erasing your analytics person and events). Residual copies may remain in encrypted backups for up to 30 days before being purged

6. Your Rights & Choices

  • Access & portability: You can download a copy of your personal data from within the app ("Download my data" in Account settings), and it is emailed to you as a machine-readable file. You may also request a copy by emailing us
  • Correction: You may update your profile at any time within the app
  • Deletion: You can delete your account from within the app (Account settings → Delete account). Deletion runs on a 30-day grace period during which signing back in cancels it; after that your account and associated data are permanently removed. You can also request deletion without the app from our account deletion page or by emailing us
  • Withdraw consent: You can turn off Adrian and other AI features, and change your ad and tracking choices, at any time from the "Privacy & AI" section of Account settings. Withdrawing AI consent is as easy as granting it
  • Permissions: You may revoke location, microphone, camera, photo library, or notification permissions at any time in your device settings
  • Blocking: You may block or report other users, and report AI-generated content, directly within the app

7. Security

We use industry-standard encryption in transit (HTTPS/TLS) for all communication between the app and our backend, and your data is encrypted at rest in our database and file storage. Passwords are hashed by Supabase and are never stored in plaintext. No system is perfectly secure, and we cannot guarantee absolute security.

Your account can be signed in on one device at a time. Signing in somewhere new signs out the device you were using before, and that device is told why — so an unexpected sign-out is a signal that someone else may have your password, not a glitch. We keep the sign-in records described in section 2.6 so you can check recent activity yourself (Account settings → Devices & sign-in activity), spot a sign-in you don't recognise, and end every other session at once. Changing your password also signs out every other device.

8. Children & Age Verification

WhyNot is intended for users aged 18 and older. We do not knowingly allow anyone under 18 to create or hold an account. Our Child Safety Standards describe our zero-tolerance policy toward child sexual abuse and exploitation.

When a person attempts to create an account and provides a date of birth indicating they are under the age of 18, we record limited information about the attempt for the sole purpose of enforcing our 18-and-older requirement. The recorded data includes:

  • The email address used at sign-up
  • The date of birth submitted
  • The operating system platform (iOS or Android)
  • The timestamp of the attempt

This record prevents the account from being created until the person reaches the age of 18, after which the block is automatically released. This data is used only to enforce our age policy and is not used for marketing, profiling, or any other purpose. Once the block has lapsed, you (or a parent or guardian) may email us to have the record deleted, and we will do so promptly.

If you believe a minor has provided us with personal data outside of this age-verification flow, contact us at the address below and we will delete it.

9. International Users

The app's backend and the third-party processors listed in section 4 process your data in the United States and, in some cases, other countries whose data-protection laws may differ from those of your home country. Where your data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards: transfers to providers certified under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) rely on that certification, and other transfers are covered by Standard Contractual Clauses incorporated into our data-processing agreements with the providers listed in section 4.

10. Changes to This Policy

We may update this Privacy Policy from time to time, and the "Last updated" date at the top of this page always reflects the current version. If we make a material change — for example, collecting a new category of data, adding a new subprocessor, or using existing data for a new purpose — we will notify you before the change takes effect, by email or by an in-app notice, and where the change concerns processing based on your consent we will ask for that consent rather than assume it. Minor clarifications and editorial changes may be made by updating this page alone.

11. Contact

For any privacy-related questions, data access requests, or deletion requests, email us at stump865+privacypolicy@gmail.com. We will respond within a reasonable timeframe.


© 2026 WhyNot.

? WhyNot

Stop swiping. Start saying yes. Adrian finds someone worth meeting, plans the date, and nudges you out the door.

Product

  • How it works
  • Meet Adrian
  • About
  • FAQ

Legal

  • Privacy Policy
  • Terms of Service
  • Community Guidelines
  • Child Safety Standards
  • Accessibility

Support

  • Get help
  • Contact us
  • Delete your account
  • Email us
© 2026 WhyNot · Stop swiping. Start saying yes. Made with one small “why not?” at a time.