trust

Privacy policy

last updated 24 August 2026

draft, pending legal review

imero exists so that people can explore a part of their life in privacy. That only works if we treat your data the way we would want ours treated. This policy explains, in plain words, what we store, why, and what you can do about it.

Who we are

The data controller is imero (company details follow upon incorporation), Netherlands. A data protection officer will be appointed before launch, and their contact details will appear here. Until then, privacy questions go to the address on our contact page.

What we store and why

Your account

A handle, a sign-in method (a passkey or an email link), and your invite chain. You never need to show a real name publicly. Each person in a couple account can choose how their display name appears: full, initial only, or hidden.

Your profile

What you write about yourself and the preferences you choose to show. You control the visibility of every part of it, field by field.

Lifestyle and orientation details

Anything that reveals your sexual orientation or lifestyle is special category data under Article 9 of the GDPR. We treat it accordingly:

  • It is stored encrypted.
  • It sits behind a separate consent, distinct from your general acceptance of the terms.
  • You can withdraw that consent at any time. Withdrawal purges those fields; they are not archived or kept "just in case".

Your photos

Original photos never leave our server. Other members only ever see permitted derivatives, including blurred versions wherever you have chosen blur. Location and device metadata (EXIF) is stripped the moment you upload.

Your messages

Chat messages are encrypted at the application level. Staff cannot browse conversations. Decryption is possible only when a participant reports a conversation, and even then it is time-boxed to that report and every access is written to an audit log.

Your location

We never store your coordinates. Your position is reduced to a coarse geohash cell, and other members only ever see distance buckets such as 0-5 km. A privacy zone hides you from anyone near your home. The one exception is club venue addresses, which are public business information.

Moderation records

Reports, decisions, and the written reasons behind them. We keep these so that appeals are possible and so that patterns of harm stay visible to our moderators. Evidence is stored as a pseudonymised snapshot, so a decision survives even after an account is deleted.

What we never do

  • We never sell your data. To anyone, in any form.
  • We never run third-party trackers, ad cookies, or adtech SDKs.
  • We never send SMS, so your phone number is never in play.
  • We never ask for or upload your address book.

Legal bases

For the lawyers among you, this is where each piece rests:

  • Contract: your account, profile, photos, and messages exist to provide the membership you signed up for.
  • Explicit consent: lifestyle and orientation details, always separately given and always withdrawable.
  • Legitimate interest: keeping the community safe, which covers moderation records and abuse prevention.
  • Legal obligation: the rare cases where the law requires us to act, such as reports involving minors.

Blur and visibility are data protection too

Some of our strongest protections are not in a database but in the product itself. Blurred photos mean a stranger scrolling past learns nothing about your face. Visibility controls mean your profile details only reach the people you have decided to show them to. Distance buckets and the privacy zone mean nobody can work out where you live. We design so that the sensitive version of you is only ever visible on your terms.

How long we keep things

  • Notifications: 90 days, then gone.
  • Profile view history: 30 days, then gone.
  • Deleted accounts: your account disappears from the platform immediately. You have a 14-day window to change your mind and restore it. After that, everything is hard deleted.

Your rights and how to use them

You do not have to email anyone to exercise your rights. The important ones are buttons in your settings:

  • Access and export: download a bundle of everything we hold about you.
  • Rectification: edit your own data at any time.
  • Deletion: delete your account in-app. Immediate disappearance, a 14-day restore window, then hard delete.
  • Consent withdrawal: switch off the special category consent at any time; those fields are purged.
  • Complaint: you can always complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority.

Analytics and error monitoring

We run our own analytics (Plausible) and error monitoring (GlitchTip) on our own servers. No visitor data goes to a third party.

  • Analytics is cookieless and anonymous: we count page views and aggregated feature usage (for example "how many sessions used search today"), never who did what. No identifiers, no cross-site tracking, no advertising profiles.
  • Error reports are technical: what broke and where. They are scrubbed before storage and carry no account identity, no cookies and no message content.

Who processes data for us

A short list, kept deliberately short:

  • Hosting: our servers, within the EU.
  • Email delivery: for sign-in links and the notifications you choose to receive.
  • Age verification partner (once launched): confirms you are an adult. The partner deletes biometric data at once; we store only "18+: yes" and a vendor reference.

International transfers

There are none. Your data is stored and processed in the EU only.

The supervisory authority

Our lead supervisory authority is the Autoriteit Persoonsgegevens in the Netherlands. You have the right to lodge a complaint with them at any time, free of charge.

Changes to this policy

If we change something meaningful, we tell you inside the platform before it takes effect, in plain words, with the old version still available. We will never bury a change in silence.

Questions about any of this? Get in touch. We answer privacy questions ourselves, not with templates.