Privacy Policy
Last updated: 26 August 2026
Thymming ("we", "the platform") is an experimental relationship platform currently in testing (MVP). This policy explains what data we collect, why, and what control you have over it. By using the platform you agree to this policy. Orientation, sexual role and neurodivergence are asked for separately, with an explicit consent step, because they are a special category of personal data under GDPR / UK GDPR.
1. Data we collect
When you sign in with Google we receive your email address. You then choose what to add to your profile: a nickname (we recommend not using your real name), date of birth, city, physical details, relationship preferences, compatibility answers (attachment style, love languages), an optional bio and an optional photo. We also store approximate coordinates for the city you choose (never your exact position), the time you were last active, and — if you turn notifications on — an identifier for each device you enable them on. We do not ask for, and you should not provide, documents, financial data or your exact address.
2. How we use your data
Matching is the main purpose: we compute compatibility indicators and the distance between city coordinates to show you relevant people. Your data is also used to run the service itself: to show whether you have been active recently, to send you notifications about messages and matches (by push and by email, according to your settings), to send account reminders and inactivity notices, to keep the platform safe when someone blocks or reports another user, and to answer you if you contact support. Your email is used for sign-in, for those notifications, and for important notices about the platform — you can turn the message and match emails off at any time in Settings.
3. What other users see
Other signed-in users within your mutual attraction spectrum can see your nickname, your age (not your date of birth), your city, the distance between you, your profile details, compatibility indicators, and whether you have been offline for a long time. Your photo stays blurred and inaccessible until you both confirm a mutual match. Your email, your date of birth and your exact location are never shown to anyone. Sexual role and neurodivergence are only revealed if you choose to share them — but note that sexual role still contributes to your compatibility indicators even when you keep it private.
4. Photos
Photos are kept in a private bucket. They are only served through temporary signed links, generated by our server after confirming a mutual match (or to you, for your own photo). Before that, every profile photo is looked at by a person on our team — see Moderation below.
5. Moderation
To keep Thymming safe we do three things that involve looking at your information. First, every profile photo is reviewed by a person on our team, to catch nudity, someone else's picture, or anyone who appears to be under 18. Second, when someone reports a profile, a moderator can see that profile's photo and the details of the report. Third, we keep a security log of administrative actions — including who looked at which photo, and when — so that this access can be checked rather than taken on trust. We do this to protect the people using the site (UK GDPR Article 6(1)(f), legitimate interests, and our duties under the Online Safety Act). Moderators do not read your private conversations except where a report points to a specific conversation.
6. Where data is stored
Data is stored with Supabase (database, authentication, file storage), whose servers for this project are in Ireland (EU). The application itself runs on Hostinger, in the United Kingdom. Access to the raw database is restricted; the application enforces row-level security rules so users can only read what the product intends them to see.
7. Cookies and local storage
We use local storage in your browser for functional preferences only: your session, theme (light/dark), language and measurement units. We do not use advertising or tracking cookies.
8. Third parties
We rely on: Google (sign-in); Supabase (database, authentication, file storage and real-time messaging); Hostinger (hosting and the mail server that sends our emails); OpenStreetMap/Nominatim (city search — only the text you type is sent, never your identity); and the push service of your own browser (Google, Apple or Mozilla, depending on the browser) to deliver notifications. The sign-in page loads a background image from Unsplash. We do not sell or share your personal data with advertisers or data brokers. Reports you submit about other users are read by the team to keep the platform safe.
9. Retention and deletion
Your data is kept while your account exists. During the testing phase, data may be reset. You can request account deletion yourself at any time in Settings: your profile, matches, messages and photo are then permanently deleted after 7 days. During those 7 days you can change your mind, but only by choosing to cancel in Settings — simply using the site does not cancel it. Accounts inactive for 6 months, and profiles never completed after 23 days, are also deleted automatically.
10. Your rights
You may access or correct your profile data at any time in Edit profile, download a copy of your personal data in Settings → Download my data, and delete your account yourself in Settings (see section 8). You can block and report other users directly in the product. For any other request about your data, contact us at the address below.
11. Contact
Questions about privacy: support@rhemfur.com.