Your privacy

D8RE Privacy Policy

Last updated: 29 September 2026

D8RE is designed around a simple principle: your private choices should remain private. This Privacy Policy explains what information D8RE processes, why it is processed, how long it may be retained, and the choices and rights available to you.

D8RE is intended for users aged 18 and over.

1. About D8RE and privacy requests

This policy covers the D8RE app and the D8RE website.

The data controller is D8RE Group, a société par actions simplifiée à associé unique (SASU), registered under SIREN 130 212 012 (RCS Paris), with its registered office at 173 rue de Courcelles, 75017 Paris, France.

For questions about the processing described here, or to exercise your privacy rights, contact the D8RE team at privacy@d8re.com.

2. No public profile or traditional account

D8RE does not require users to create a public dating profile.

In particular, D8RE does not require you to provide a public:

  • name;
  • biography;
  • photograph;
  • dating profile;
  • list of matches.

The app creates an anonymous authentication account with a pseudonymous user identifier through Supabase. This identifier connects your device to sessions, access rights and the free-session cooldown; it is not a public profile. Authentication information is stored on your device so the app can reconnect.

3. Information D8RE may process

Technical information

This may include:

  • anonymous or pseudonymous user identifiers;
  • session identifiers;
  • device and operating-system information;
  • app version;
  • technical logs necessary for security, reliability and troubleshooting.

Network requests to the website and app service providers also transmit connection information, such as an IP address and request information, needed to deliver and protect those services.

Session information

When two users start a D8RE session, the service may process:

  • pairing and session information;
  • answers selected during the session;
  • submission status;
  • mutual-match results.

The purpose of processing individual answers is to determine which choices are mutual.

D8RE is designed so that non-mutual answers are not revealed to the other participant.

Fantasy or other free-text content

Fantasy text is stored to support the feature and is revealed to the other participant only when its mutual-reveal conditions are met. If you choose to send an Epilogue or Wild Epilogue dare, that message is stored and delivered to the other participant. A recap of sent and received dares may also be saved on your device.

You should not enter:

  • another person's personal information;
  • illegal content;
  • abusive, threatening or hateful content;
  • content involving minors;
  • content describing or encouraging non-consensual sexual activity.

Some answers or free-text content may reveal information relating to a person's private or sex life. D8RE processes this information only to provide the feature requested by the user and, where required by applicable law, on the basis of the user's explicit consent.

4. Why we process information

We process information only where necessary for purposes such as:

  • creating and connecting a private D8RE session;
  • synchronising two participants;
  • recording each participant's selections;
  • calculating mutual matches;
  • enabling double-opt-in features;
  • preventing abuse or misuse;
  • maintaining security and reliability;
  • restoring a session where technically necessary;
  • applying the free-session cooldown and providing or restoring paid access;
  • complying with applicable legal obligations.

We do not use your private D8RE answers to create a public dating profile.

We do not sell your private answers or Fantasy content to advertisers or data brokers.

5. Legal bases

Where the GDPR or similar privacy laws apply, D8RE relies on one or more appropriate legal bases depending on the processing involved.

These may include:

  • providing the service requested by you;
  • your consent or explicit consent where required;
  • legitimate interests in protecting the service, preventing fraud and maintaining security;
  • compliance with legal obligations.

Where processing relies on consent, you may withdraw that consent for future processing.

6. Mutual answers and confidentiality

One of D8RE's core principles is that a participant should not learn another participant's rejected or non-mutual choices through the normal operation of the service.

Individual card choices and Fantasy content follow their applicable reveal conditions. Messages that you explicitly send through Epilogue features are shared with the other participant.

D8RE cannot, however, control information that another person independently observes, remembers, records or shares outside the service.

7. Data retention

Different information is retained for different purposes:

  • Session answers, Fantasy text and Epilogue messages are linked to a short-lived session. The current configuration sets session expiry to 30 minutes after creation and makes completed sessions eligible for deletion within 15 minutes of completion. A cleanup task is scheduled every 15 minutes to delete expired sessions and their linked content.
  • Operational error records contain a pseudonymous user identifier, an optional session identifier, an operation name, an error code, the platform and a timestamp. The configured daily cleanup deletes errors older than 30 days. Separate session-status records, which do not contain answers or free text, are eligible for cleanup 90 days after the session ends or expires.
  • Anonymous authentication identifiers, free-session usage timestamps, and purchase or entitlement records are stored separately from session content. Session cleanup does not delete them automatically; they support continued access, cooldown enforcement and purchase recovery. You can request deletion using the contact below.
  • The app stores local preferences, authentication information, session recovery information, pending submissions, access information and Epilogue recaps on your device. These are not all subject to the server session-expiry timer and may remain until the app clears or replaces them, or you clear its stored data.
  • If you contact us by email, we process your email address and the information you send to respond to your request. Correspondence is retained for handling the request and any applicable legal obligations.

Scheduled cleanup timings describe the application database configuration, not an exact erasure deadline for every copy. Cleanup delays, local device storage, service-provider logs and backups may have different lifecycles.

To request deletion of data associated with your use of D8RE, email privacy@d8re.com. Clearing device storage does not itself delete server-side records.

8. Service providers and sharing

D8RE uses the following services:

  • Supabase for anonymous authentication, the database, backend functions and realtime session synchronisation;
  • RevenueCat for iOS purchase and entitlement management, using the app's pseudonymous user identifier and purchase information;
  • Apple for iOS distribution and in-app purchases;
  • Google Play for Android distribution; Google Play billing is not enabled in the current Android closed-test build;
  • Sites hosting on Cloudflare infrastructure for the D8RE website.

Session results and messages are shared with the other participant as described above. Technical providers process information needed to deliver their services. App stores also process information under their own privacy policies.

D8RE requires third-party service providers processing personal data on its behalf to provide protection equivalent to that described in this Privacy Policy and required by the Apple App Store Review Guidelines. The applicable data-processing terms for Supabase, RevenueCat and ChatGPT Sites impose obligations concerning limited use, confidentiality, security, assistance with privacy rights, and deletion or return of data. They also require protective obligations for their subprocessors. These obligations apply to the data and services each provider actually processes for D8RE.

9. International transfers

Some technical service providers may process information outside the European Economic Area.

Where required by applicable law, D8RE will rely on appropriate legal safeguards for international transfers of personal data.

10. Payments and access rights

In the current iOS app, purchases are handled through Apple and verified using RevenueCat and the D8RE backend. D8RE processes purchase identifiers, product and transaction information, purchase or expiry dates, and entitlement status linked to the app's pseudonymous identifier to provide and restore access.

D8RE does not receive your full payment-card details from Apple. Google Play billing is not enabled in the current Android closed-test build.

11. Operational monitoring and advertising

The current app records the operational errors and session-status information described above for reliability and troubleshooting. These monitoring records do not contain card answers, Fantasy text or Epilogue messages.

The current app and website do not integrate an advertising or third-party behavioural-analytics service. Hosting and backend providers still process the connection information needed to serve and protect requests.

12. Security

D8RE uses technical and organisational measures intended to protect information against unauthorised access, alteration, disclosure or destruction.

The app connects to its backend services over HTTPS. Private session data is protected by authentication and access controls; this should not be understood as a claim of end-to-end encryption.

No online service can guarantee absolute security.

13. Your privacy rights

Depending on where you live, you may have rights including:

  • access to your personal data;
  • correction of inaccurate data;
  • deletion;
  • restriction of processing;
  • objection to certain processing;
  • data portability where applicable;
  • withdrawal of consent;
  • the right to lodge a complaint with a competent data-protection authority.

For users in France, the competent supervisory authority is the CNIL.

Access, correction or deletion requests may be sent to: privacy@d8re.com

Because D8RE uses pseudonymous identifiers rather than a traditional account, we may need information sufficient to locate and verify the relevant records. Please do not include private session answers or full payment details in your initial request. We cannot retrieve information that has already been deleted or irreversibly anonymised.

14. Users under 18

D8RE is intended exclusively for adults aged 18 or over.

Users under 18 must not use the service.

If we become aware that information relating to a minor has been submitted contrary to these Terms, we may delete it and take appropriate protective measures.

15. Changes to this Privacy Policy

We may update this Privacy Policy as D8RE evolves or where required by law.

The current version will always display its latest revision date.

Material changes will be communicated where required.

16. Contact

For questions about privacy or personal data:

privacy@d8re.com