Table of Contents

  1. Introduction & Scope
  2. Data Controller
  3. Information We Collect
  4. Legal Bases for Processing
  5. How We Use Your Information
  6. AI & On-Device Processing
  7. Data Sharing & Disclosure
  8. Cookies & Tracking Technologies
  9. Data Storage & Security
  10. Data Retention Schedule
  11. Your Rights & Choices
  12. GDPR — European Users
  13. CCPA / CPRA — California Users
  14. Other U.S. State Privacy Laws
  15. International Data Transfers
  16. Children's Privacy
  17. Biometric & Sensitive Data
  18. Third-Party Services
  19. Changes to This Policy
  20. Contact & Data Protection Officer

1. Introduction & Scope

Persona Group ("Persona," "we," "our," or "us") operates the Persona - AI Dating mobile application and the website at persona-us.com (collectively, the "Service"). This Privacy Policy describes how we collect, use, disclose, and safeguard your personal information when you access or use our Service.

By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use the Service.

This Policy applies to all users worldwide. If you reside in a jurisdiction with specific data protection requirements — such as the European Economic Area (EEA), United Kingdom, California, or other U.S. states with comprehensive privacy laws — please also review the jurisdiction-specific sections below.

2. Data Controller

For the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection legislation, the data controller is:

Persona Group
Email: privacy@persona-us.com
Data Protection Officer: dpo@persona-us.com

3. Information We Collect

3.1 Information You Provide Directly

3.2 Information Collected Automatically

3.3 Information from Third Parties

5. How We Use Your Information

6. AI & On-Device Processing

🔒 Privacy-First AI

Persona's artificial intelligence runs entirely on your device using Apple's Core ML framework. Your personality quiz responses are processed locally to generate your OCEAN (Big Five) personality profile. This data is never sent to external AI services (no OpenAI, no cloud ML).

Here is what our on-device AI does:

What is stored on our servers: Only your computed personality dimension scores (numerical values, 0.0–1.0) are synced to our database for matching purposes. Raw quiz responses and the AI model's intermediate computations remain on your device.

Automated Decision-Making (GDPR Art. 22): Our matching algorithm makes automated suggestions but does not produce legal or similarly significant effects. You always decide whom to connect with. You have the right to request human review of any automated matching decision by contacting us.

7. Data Sharing & Disclosure

We do not sell your personal data. We do not share your data with data brokers. We disclose information only in the following limited circumstances:

7.1 With Other Users

Your public profile — including your name, photos, bio, age, and personality traits you choose to reveal — is visible to other users for matching purposes. Messages are shared only with the specific user you are chatting with.

7.2 Service Providers

We use a limited number of service providers, each bound by data processing agreements (DPAs):

7.3 Legal Requirements

We may disclose your data when we believe in good faith that disclosure is necessary to:

7.4 Business Transfers

If Persona Group is involved in a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change in ownership or control via the app or email.

8. Cookies & Tracking Technologies

Mobile App: Persona does not use traditional browser cookies. We use standard iOS storage mechanisms:

Website (persona-us.com): Our landing page uses localStorage to remember waitlist sign-up status. We do not use third-party tracking cookies, advertising pixels, or analytics services on our website. For more details, see our Cookie & Data Policy.

App Tracking Transparency (ATT): Persona does not track you across other companies' apps and websites. We do not request ATT permission because we do not engage in cross-app tracking as defined by Apple.

9. Data Storage & Security

We implement industry-standard technical and organizational measures to protect your data:

10. Data Retention Schedule

We retain your data only as long as necessary for the purposes described in this Policy:

  • Active Account Data: Retained for the lifetime of your account.
  • Deleted Accounts: All personal data is permanently deleted within 30 days of account deletion. This includes your profile, photos, messages, personality scores, and match history.
  • Chat Messages: Stored for the lifetime of both participants' accounts. Deleted when either party deletes their account (messages are removed from both sides).
  • Device Tokens: Removed when you disable notifications, uninstall the app, or delete your account.
  • Transaction Records: Subscription transaction IDs and receipts are retained for 3 years after the transaction for financial/tax compliance and dispute resolution.
  • Safety Reports: Reports of abuse, harassment, or safety concerns — and related evidence — are retained for 2 years after resolution to support safety investigations and legal proceedings.
  • Anonymized Analytics: Aggregated, fully de-identified usage statistics may be retained indefinitely. These cannot be linked back to any individual.
  • Legal Hold: If data is subject to a legal hold, preservation request, or active investigation, it will be retained until the matter is resolved, regardless of normal retention periods.

11. Your Rights & Choices

Regardless of where you reside, we provide all users with the following rights:

How to exercise your rights: Email privacy@persona-us.com with the subject line "Privacy Rights Request." We will verify your identity and respond within 30 days (or sooner if required by applicable law). You may also submit requests through Settings → Privacy in the app.

12. GDPR — European Users

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation:

Data Protection Officer: You may contact our DPO at dpo@persona-us.com for any GDPR-related inquiries.

Legal Basis Summary: See Section 4 above. For special categories of data (sexual orientation, gender identity), we rely on your explicit consent per Art. 9(2)(a) GDPR.

13. CCPA / CPRA — California Users

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

Categories of Personal Information Collected (Cal. Civ. Code § 1798.100)

Your CCPA/CPRA Rights

Authorized Agents: You may designate an authorized agent to exercise your rights on your behalf. The agent must provide signed written authorization and we may verify your identity directly.

Verification: We will verify your identity by matching information you provide with data in our records. For deletion requests, we may require re-authentication.

Financial Incentives: We do not offer financial incentives for the collection or retention of personal information.

Contact for CCPA requests: privacy@persona-us.com with the subject "CCPA Request." We will respond within 45 days.

14. Other U.S. State Privacy Laws

We also respect privacy rights under comprehensive state privacy laws, including but not limited to:

CalOPPA Compliance: In accordance with the California Online Privacy Protection Act, we will notify users of material changes to this policy, honor Do Not Track browser signals to the extent technically feasible, and allow users to review and change personal information by logging into their account.

15. International Data Transfers

Your personal data is primarily stored in the United States (AWS us-east-1 via Supabase). If you are located outside the United States, your data will be transferred to and processed in the US.

For transfers from the EEA/UK/Switzerland to the US, we rely on:

16. Children's Privacy

Persona is rated 17+ on the App Store and is intended exclusively for adults. We do not knowingly collect, solicit, or maintain personal information from anyone under 17 years of age.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately at privacy@persona-us.com. We will take prompt steps to delete the information.

COPPA: In compliance with the Children's Online Privacy Protection Act, if we discover that we have inadvertently collected information from a child under 13, we will delete such information without delay.

17. Biometric & Sensitive Data

Biometric Authentication: Persona supports Face ID and Touch ID for optional biometric app locking. This biometric processing is handled entirely by Apple's LocalAuthentication framework on your device. We never receive, store, or transmit your biometric data (facial geometry, fingerprint data). Apple does not share biometric data with any app.

Sensitive Personal Information: If you voluntarily provide sensitive data in your profile (e.g., sexual orientation, gender identity), it is stored in our database solely for matching purposes and displayed only to potential matches. You may remove this data at any time by editing your profile.

Illinois BIPA Compliance: We do not collect, capture, purchase, or otherwise obtain biometric identifiers or biometric information as defined under the Illinois Biometric Information Privacy Act (BIPA).

18. Third-Party Services

Our Service integrates with a limited number of third-party services. Each operates under its own privacy policy:

We do not integrate with third-party advertising networks, social media trackers, or analytics platforms (no Google Analytics, no Facebook SDK, no Firebase, no Amplitude).

19. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service itself. When we make material changes:

We encourage you to review this Policy periodically. Your continued use of the Service after changes are posted constitutes acceptance of the updated Policy.

20. Contact & Data Protection Officer

If you have questions, concerns, or wish to exercise your privacy rights:

General Privacy Inquiries

privacy@persona-us.com

Data Protection Officer

dpo@persona-us.com

CCPA / U.S. State Requests

privacy@persona-us.com
Subject: "CCPA Request"

Support

support@persona-us.com
In-App: Settings → Help & Support