courtme.ai Back to home

courtme.ai: Privacy Policy

Effective Date: 2026-07-13 Last Updated: 2026-07-07 Entity: courtme.ai, Inc. (Delaware C-Corporation; principal place of business: Austin, TX) Contact: privacy@courtme.ai


1. Plain-language summary (TL;DR)

  • We collect personal information, including sensitive data like sexual orientation (inferred from your matches), precise location, and gender identity, to run an AI-powered dating service.
  • We use your data to train and improve our AI matchmaking model. You can opt out (see Section 8).
  • Your messages and your conversations with our AI matchmaker are stored on our servers (they are not end-to-end encrypted), and trained staff may review them for safety, support, moderation, and to improve matching. Each such review is purpose-limited and audit-logged. See Sections 3.6 and 9.
  • We share data with advertising partners (Meta, Google) for marketing. Under California law (CCPA/CPRA), this is considered a "sale" / "share" of personal information. You can opt out via the "Do Not Sell or Share My Personal Information" link in our footer.
  • You have rights to access, correct, delete, and port your data. See Section 9.
  • We do not knowingly collect data from anyone under 18.
  • We retain data only as long as needed. See Section 10.

This summary does not replace the full Policy below.


2. Information we collect

2.1 Information you provide

  • Name, email, phone number
  • Date of birth (we verify you are 18+)
  • Gender and gender identity
  • City and approximate location
  • Photos
  • Profile information, including biographical text, dating preferences, "tell your AI matchmaker" prompts, personality questionnaire answers, pain-point questionnaire answers, dating intent
  • Identity verification documents (government ID via Stripe Identity, when required)
  • Payment information (processed by Stripe; we do not store full card numbers)
  • Payout handles for promotional refunds (e.g., Venmo username or PayPal email), when you claim a refund under our 3 in 30 Guarantee or similar promotional offer
  • Emergency contact information
  • Date feedback, reports, and unmatch reasons
  • Communications you send to courtme (support emails, in-app reports)
  • Messages and content you exchange with other users (one-to-one match chats, event chats, and group chats)
  • Your conversations with our AI matchmaker ("Courtney"), including onboarding and intake interviews conducted by voice and/or text
  • Audio recordings and transcripts of your voice interactions with our AI matchmaker (voice intake)
  • Biometric data (facial geometry) generated when we match your verification selfie to your government ID to confirm your identity and that you are 18+ (see our Biometric Data Notice)

2.2 Information collected automatically

  • Device and technical data: device type, OS, app version, IP address, language preferences, time zone
  • Usage data: pages and screens viewed, actions taken (matches approved, dates booked, messages opened), session duration, referral source
  • Location data: city- and ZIP-level location at minimum; precise GPS location if you grant permission (for venue suggestions and date coordination)
  • Cookies and similar technologies: see Section 6

2.3 Information from third parties

  • Identity verification: Stripe Identity returns verification status
  • Photo moderation and identity verification: AWS Rekognition returns (a) content-classification results for photo moderation, and (b) face-match results when verifying your identity by comparing your selfie to your government ID. The identity face-match uses biometric data (facial geometry) and is governed by our Biometric Data Notice
  • Advertising partners: Meta, Google, and similar may share back conversion/audience data
  • Referrals: when another user refers you, we may receive your contact info from them

2.4 Sensitive Personal Information (SPI)

We collect or infer the following categories defined as Sensitive Personal Information under California CPRA (and equivalent under other state laws):

  • Precise geolocation (when you grant permission)
  • Sexual orientation (often inferred from match patterns or preferences you provide)
  • Gender identity (when you provide it)
  • Racial or ethnic origin (if you choose to provide it)
  • Government ID information (for identity verification)
  • Biometric identifiers (facial geometry), generated only to verify your identity by matching your selfie to your government ID; see our Biometric Data Notice for how we obtain consent, use, and destroy this data. We never use biometric data for advertising or AI training
  • Account credentials (in combination with passwords)

We use SPI only for the purposes you would reasonably expect in a dating service (matching, safety, identity verification) and not for inferring characteristics about you for any other purpose. You may limit our use of SPI by contacting privacy@courtme.ai.


3. How we use your information

3.1 To provide the service

  • Create your account and build your profile
  • Run our AI matchmaking system to suggest matches
  • Coordinate dates (venue suggestions, scheduling, confirmations)
  • Run safety check-ins and respond to safety incidents
  • Verify identities and prevent fraud
  • Process payments and operate the token system

3.2 To improve the service, including AI model training

We use your data to train, evaluate, and improve our AI matchmaking and supporting models. This includes (but is not limited to):

  • Your profile content, photos, questionnaires, and preferences
  • Your match decisions (approve / pass) and post-date feedback
  • Date outcomes (whether the date happened, mutual see-again rate)
  • Aggregated patterns across users to refine compatibility scoring

We aim to use de-identified or aggregated data for training where feasible. Where individual data is used:

  • It is stored separately from your account and access-controlled
  • It is not used to identify you publicly or shared in identifiable form with third parties for their own AI training

You may opt out of AI training by contacting privacy@courtme.ai with the subject line "AI Training Opt-Out." Opting out does not delete data already used in prior training runs (which is technically impractical to reverse) but excludes your data from future training. We never use your biometric data (facial geometry) or voice-identification data for model training, regardless of any setting.

3.3 To communicate with you

  • Transactional emails and push notifications (matches, dates, safety check-ins)
  • Lifecycle marketing (you may opt out of marketing at any time)
  • Support and policy responses
  • Product updates

3.4 To market courtme

  • Run advertising campaigns (Meta, Google, TikTok)
  • Build "lookalike" audiences based on existing users
  • Measure ad effectiveness and attribution

3.5 To meet legal and safety obligations

  • Respond to law enforcement requests (with legal process)
  • Investigate safety incidents and abuse reports
  • Defend legal claims
  • Comply with applicable laws

3.6 To review communications for safety, support, and product quality

Your in-app messages are stored on our servers and are not end-to-end encrypted. Authorized courtme personnel may review the content of:

  • messages you exchange with other users (match, event, and group chats), and
  • your conversations with our AI matchmaker ("Courtney"), including intake interviews,

for safety and abuse investigation, fraud and ban-evasion prevention, moderation, responding to your support requests and disputes, product-quality review, and improving our matching and AI systems. (Your AI-training opt-out in Section 8 excludes your content from future model training, but not from safety, support, or legal review.)

This internal access is role-limited, purpose-scoped, and audit-logged: only trained Trust & Safety and product/research staff may reach this content, each access is tied to a specific purpose (for example safety, moderation, support, research, product quality, or legal) and a stated reason, and every access is recorded in an internal audit log. Retaining messages on our servers rather than end-to-end encrypting them is what makes this safety and support review possible, and is standard practice for dating and messaging services; the access controls and audit logging above are the safeguards on it.


4. Sharing of information: including SALES/SHARES under California law

4.1 Service providers (subprocessors)

We share personal information with the vendors below, each bound by a data processing agreement (DPA) to use the data only to provide services to us. We maintain and update this list as our subprocessors change.

Subprocessor Purpose Data involved
Supabase Database, authentication, file storage Account, profile, messages, photos
Anthropic AI matchmaking, bio generation, content-moderation classifiers Profile, prompts, messages/intake (pseudonymized where feasible)
AWS - Amazon Rekognition (a) Photo content moderation; (b) biometric face-matching for identity verification (selfie↔ID) Photos; facial geometry (see Biometric Data Notice)
Stripe Payments; identity and age verification (Stripe Identity) Payment info, government ID, DOB, verification status
Twilio SMS: safety check-ins, emergency-contact alerts, verification codes Your phone number and your emergency contact's phone number
LiveKit Real-time voice transport for AI intake Voice audio stream
Deepgram Speech-to-text transcription of voice intake Voice audio, transcripts
ElevenLabs Text-to-speech for the AI matchmaker's voice Intake text/audio
PostHog Product analytics Usage/event data, identifiers
Sentry Error and crash monitoring Diagnostics, IP address, identifiers
Inngest Background job orchestration Data needed to run scheduled/async jobs
Resend Transactional and lifecycle email Email address, message content
Vercel Web hosting IP address, request logs
Expo / EAS Mobile builds and push-notification delivery Device/push tokens
Google Places API (venue data); Analytics/Ads (see 4.2) Venue queries; usage/conversion data
Apple / Google (app stores) App distribution, push, in-app purchases, and age-signal where available Purchase records, push tokens, age category
Venmo (PayPal, Inc.) / PayPal Promotional refund payouts (3 in 30) - only if you elect one Payout handle, refund amount

We do not use OpenAI as a subprocessor at this time; if that changes, we will update this list.

4.2 Advertising and analytics partners: TREATED AS "SALE"/"SHARE" UNDER CCPA/CPRA

We share information with the following partners for advertising and analytics. Under the California Consumer Privacy Act / CPRA, the activities below are legally categorized as "sale" or "sharing" of your personal information, even though no money changes hands directly for the data:

  • Meta (Facebook/Instagram), via Meta Pixel and Conversions API. We share signup events, page views, and audience data for ad targeting, optimization, and lookalike modeling.
  • Google: Google Analytics and Google Ads. We share usage and conversion data.
  • TikTok (if active): TikTok Pixel for ad attribution.
  • Other ad-tech partners as we onboard them.

You have the right to opt out of this sale/sharing. Use the "Do Not Sell or Share My Personal Information" link in our footer, or email privacy@courtme.ai. We will honor Global Privacy Control (GPC) signals as opt-outs.

We do not sell or share Sensitive Personal Information for purposes other than those you'd reasonably expect.

4.3 Other users

  • Your profile, photos, and AI-generated bio are visible to your matches
  • Date coordination details are shared with the user you're going on a date with
  • Reports you submit may be reviewed by our moderation team and, in serious cases, shared with law enforcement

4.4 Business transfers

If courtme is acquired, merged, or sells assets, your data may transfer to the acquirer. We will notify you before the transfer if your rights would meaningfully change.

4.5 Legal disclosure

We disclose data when legally compelled (subpoena, court order, government request) and when necessary to investigate suspected fraud, threats, or violations of our terms.


5. Automated decision-making (AI matchmaking)

Our matchmaking system uses automated processes, including AI / large language models, to score and suggest matches. Specifically:

  • We generate compatibility scores using AI prompts that consider your profile, preferences, and prior decisions
  • We do not make decisions about you with legal or similarly significant effect using AI alone (e.g., we do not deny services, employment, or credit based on AI)
  • You may request a human review of any AI-driven decision affecting you (e.g., if a match was removed for moderation reasons) by emailing privacy@courtme.ai

If you are an EU/UK resident, you have additional rights under GDPR Article 22 regarding automated decision-making. See Section 9.4.


6. Cookies and similar technologies

We use cookies, SDKs, and similar technologies for:

  • Essential: session, authentication, fraud prevention (always on)
  • Performance: analytics (Google Analytics, PostHog)
  • Advertising: Meta Pixel, Google Ads tag, TikTok Pixel

You can manage non-essential cookies via our cookie banner on first visit and through your account settings. You can also use browser controls or Global Privacy Control (GPC) signals.


7. Your privacy rights

Depending on where you live, you may have the following rights:

7.1 All users

  • Access: request a copy of personal information we hold about you
  • Correct: fix inaccurate data
  • Delete: request erasure (subject to legal/safety exceptions)
  • Port: receive your data in a machine-readable format
  • Object/Limit: to certain uses including AI training, marketing, sale/share

7.2 California residents (CCPA/CPRA)

  • Right to know categories and specific pieces of personal information collected
  • Right to opt out of "sale" and "sharing" (advertising, see Section 4.2)
  • Right to limit use of Sensitive Personal Information
  • Right to delete
  • Right to correct
  • Right to data portability
  • Right to non-discrimination for exercising these rights

To submit a request, use the "Do Not Sell or Share My Personal Information" link or email privacy@courtme.ai. We respond within 45 days (extendable by 45 with notice).

7.3 Texas, Colorado, Connecticut, Virginia, Utah, and other state law residents

You have substantially similar rights under your state's law. Submit requests to privacy@courtme.ai.

7.4 EU/UK residents (GDPR)

  • All rights above plus the right to object to processing, the right to restrict processing, and the right to lodge a complaint with your data protection authority
  • Right to human review of automated decisions (Article 22)
  • Our lawful bases for processing: contract performance (running the service), legitimate interests (safety, fraud prevention, improvement), consent (marketing, SPI uses requiring consent), and legal obligations

8. Opting out of AI training and "sale"/"share"

AI training opt-out: You can opt out of the use of your data for AI model training through your in-app privacy settings (where available) or by emailing privacy@courtme.ai with the subject line "AI Training Opt-Out." We will exclude your data from future training runs and log your request. Data already used in past training is not technically reversible. We never use your biometric data (facial geometry) or voice-identification data for model training, regardless of this setting.

Sale/Share opt-out: Use the "Do Not Sell or Share My Personal Information" link in our footer, or send GPC signals via your browser. We honor GPC.


9. Data retention

We keep personal information only as long as needed for the purposes in this Policy, then delete or de-identify it. When you delete your account, we remove your data on the timeline below, subject to the exceptions that follow.

9.1 Standard timelines

  • Active accounts: while your account is active.
  • Inactive accounts (no login for 24 months): we may delete or anonymize the account.
  • On account deletion - your solo data (profile, photos, AI-matchmaker "Courtney" intake and transcripts, your own settings): soft-deleted immediately and purged from production systems within 30 days, and from backups on our normal backup cycle.
  • Two-person chats (match, event, and group messages): because these conversations also belong to the other participant(s), when you delete your account we redact your identity from shared threads (removing your name and profile), but the conversation content may be retained for the other participant and for safety, subject to the exceptions below. Messages are retained server-side and are not end-to-end encrypted (see Section 3.6).
  • Voice-intake audio: raw audio is deleted shortly after transcription; the transcript follows the Courtney-intake timeline above.
  • IP address and authentication logs: retained up to 90 days for security and fraud prevention, then purged (unless subject to a preservation request or legal hold).

9.2 Exceptions - data we retain after deletion

  • Financial records (tax/audit): on deletion we strip identity from token-transaction and purchase-receipt records and retain the de-identified records (amounts, dates, tax fields) for accounting, tax, and audit purposes for the period required by law (generally around 7 years). De-identification is designed to be irreversible, and these records are no longer linked to you.
  • Safety records: reports, safety-related blocks, safety incidents, ban records, and their associated chats are retained after deletion for safety, abuse-prevention, and legal-defense purposes - at least 1 year for ordinary matters and up to 7 years (or the applicable limitations period, whichever is longer) for serious incidents (e.g., assault, threats, sex-offender enforcement). Child-safety (CSAM) material is handled and preserved as required by 18 U.S.C. §2258A.
  • Legal hold: anything subject to an active report, investigation, litigation, subpoena, or law-enforcement or legal-preservation request is retained until the matter and any preservation obligation ends.
  • Confirmed in-person ("We met") event matches: where both people confirmed they met in person, the match and its chat remain until either person unmatches or deletes (see Section 12A).
  • Aggregated/de-identified data used to improve our models may be retained indefinitely. Biometric and voice-identification data are never used for model training (see Sections 2.4 and 8).

Internal staff access to retained messages and intake is audit-logged and purpose-scoped (see Section 3.6).


10. Security

We use industry-standard measures including encryption at rest and in transit, access controls, and audit logging. No system is perfectly secure. If we discover a breach of your personal information, we will notify you and applicable regulators as required by law.


11. Children

courtme is 18+ only. We do not knowingly collect data from anyone under 18 years of age. If our age verification (or any other signal) indicates you are under 18, we block account creation and purge the associated sign-up data - including email address and phone number - from our systems, retaining only the minimal, non-identifying information needed to prevent immediate re-registration. If we otherwise learn we have collected data from a minor, we will delete it. If you believe a minor is using courtme, contact safety@courtme.ai.


12. International users

courtme is operated from the United States. If you access courtme from outside the US, your data will be transferred to and processed in the US.

For EU/UK users, we use Standard Contractual Clauses (SCCs) or equivalent safeguards for transfers outside the EEA/UK.


12A. IRL Mode & Events

When you join courtme at a partner event ("IRL Mode") - e.g., by scanning an event QR code or entering a join code - the following applies in addition to the rest of this Policy:

  • What we collect at events: the event you joined and the host/QR code that referred you, the profile information you create (including selected intent - networking, friendship, romance), your in-app activity at the event, and the standard account, device, and usage data in Section 1.
  • Event location: we determine your event association from the QR code or join code you scan or enter - not from continuous or precise location tracking. If you separately grant precise-location permission (for example, for venue suggestions), that is optional and is Sensitive Personal Information subject to your right to limit its use (Section 2.4).
  • Event matches are temporary; your account is not. The matches generated for an event are removed after the event ends, except matches where both people confirm in-app that they met in person ("We met") - those matches and their chat threads remain active until either person unmatches or deletes their account. Your account, profile, and messages are retained on our systems (subject to Section 9, Data Retention) - removing event matches does not delete your account or your data.
  • What the host sees: event hosts receive aggregate statistics only (scans, signups, matches). Hosts do not receive your name, contact details, profile, or messages.
  • Event & promotional notifications: we may send in-app push notifications about future events from the host whose event you joined, and about courtme. You can opt out in your notification settings (service/safety messages may still be sent).
  • In-app advertising: we may show advertising or sponsored placements in the app, handled under the advertising and "sale/sharing" disclosures in Sections 6–8; your opt-out rights there continue to apply.

13. Changes to this Policy

We may update this Policy. Material changes will be communicated by email and in-app notice. Continued use after the effective date constitutes acceptance.


14. Contact

  • Privacy questions / requests: privacy@courtme.ai
  • Safety: safety@courtme.ai
  • General: hello@courtme.ai
  • Mailing address: CourtMe, Inc., 5900 Balcones Drive, Ste 100, Austin, TX 78731, USA

For EU residents, our EU representative is: not yet appointed; EU users may contact privacy@courtme.ai.

© 2026 CourtMe, Inc. · All rights reserved · Privacy Policy · Terms of Service · Age Policy · Safety · Community · Do Not Sell or Share