Privacy Policy
Version 1.0 · effective on launch · Dor Dor Ltd, London, United Kingdom (the controller). Contact: privacy@dordorapp.com.
What we collect and why
This list is generated from the same registry our code enforces: a field that holds personal data cannot ship without being listed here.
| Data | Why | Protection |
|---|---|---|
| Email or phone number | Sign-in codes, account recovery | Encrypted at rest; a keyed hash is used for lookups; never shown to other users |
| Apple / Google account identifier | Sign in with Apple or Google | Only the provider's opaque id; Apple private relay addresses are supported |
| First name, date of birth, gender, who you want to see | Your card and the deck; 18+ check | Other users see your age, never your birthday. "Show me" is never stored as an orientation. |
| City | Matching within your city or nearby cities | Your device's position is used once to find your city and then discarded. No exact coordinates are stored anywhere. |
| Photos and optional profile sections | Your profile | Metadata (including GPS) is stripped when a photo is uploaded; photos are served through short-lived signed links only |
| Verification selfie | The verified badge | Compared with your photos and deleted within the hour |
| Messages | Chat between matches | Encrypted at rest; deleted 30 days after a match ends or when an account is deleted |
| Swipes, matches, blocks, reports | Running the service and keeping it safe | Reports are kept two years with the reporter pseudonymised |
| Device identifier, push token, hashed device fingerprint | Notifications; sign-out-everywhere; keeping banned users out | Push tokens are pruned when a device disappears |
| Purchase history (store transaction ids) | Premium and consumables | Payments are processed by Apple or Google; we never see card details |
| Product analytics | Improving Dor Dor | Explicit events only (no session recording); no advertising or tracking across apps |
Legal bases (UK GDPR)
Contract, for running the service you signed up for. Legitimate interests, for safety and fraud prevention. Explicit consent for anything that could reveal religion or sexual orientation: "Religious practice" is an optional section you add yourself, and "Show me: everyone" is never inferred into a stored orientation.
Who processes data for us
Cloudflare (hosting edge and photo storage, EU), our EU hosting provider, RevenueCat (purchases), Twilio (SMS codes), Hive (photo moderation), AWS Rekognition (selfie verification, EU region), Sentry (crash reports, with personal data scrubbed), PostHog (analytics, EU). Data stays in the EU/UK; none of these providers may use it for their own purposes.
Retention
Passes: 90 days. Messages: 30 days after a match closes. Verification selfies: under an hour. Push tokens: on rotation. Reports: 2 years, pseudonymised. Account data: fully deleted 14 days after you ask (the grace period), backups roll off within 35 days.
Your rights
Access, rectification, erasure, restriction, portability and objection. In the app: Settings → Account → Download my data / Delete account. On the web: dordorapp.com/account/delete. Or email privacy@dordorapp.com. You can complain to the ICO (ico.org.uk).
Children
Dor Dor is for adults. Age is checked at sign-up, photo moderation flags apparent minors, and any report of an under-18 is reviewed the same day.
If privacy is a safety matter for you
Dor Dor is built for Persians living outside Iran; we do not distribute the app in Iran and take no payments from anyone resident there. We still designed for the people whose private life carries a risk: first name only, city-level location, no phone or email ever shown, an optional biometric lock, and a "hide from Iranian cities" setting. That setting keeps your card out of the deck and the flashes grid of anyone whose chosen city is in Iran. We only ever know the city a person picks, so it cannot detect someone who picks a different city. Please also read our safety page.