single.is Privacy Policy
Version and effective date: 11 August 2026
1. Controller and contact
Papaya ehf., company ID 430317-0160, Bleikjukvísl 11, 110 Reykjavík, Iceland, is the controller for the processing described here. Contact and rights requests: single@single.is.
Papaya has not appointed a Data Protection Officer at this version date. The need is reviewed regularly, particularly if regular systematic monitoring or special-category processing becomes large-scale.
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Identity and age | Kenni verification, pseudonymous lookup value, verification time, name, birth date/age, and where available phone number | Kenni and you |
| Account and profile | email, name, photos, bio, gender, postcode, approximate municipality, children, smoking, housing and occupation status | you |
| Matching choices | opposite-sex choice, age range, ranked answers, priorities and consent state | you |
| Matching processing | rule-based compatibility, reasons, optional AI score, and human introduction decision | system and Papaya |
| Dates | introduction, acceptance/rejection, time, public venue, change proposals, attendance and feedback | users and system |
| Communication and safety | private messages, read state, blocks, reports, reasons, related material and review action | users and Papaya |
| Device, purchase and operations | push token, app version, language, timestamps, Apple transaction ID, error classes and limited operational/security logs | automatically or Apple |
| Legal site and mailing list | IP, browser details, path and time; email, subscription state and delivery data if selected | device, vendors and you |
Kenni returns a national ID inside the closed verification flow. It is used transiently to verify identity and age and locate the correct account. After verification, single.is ordinarily retains only a secret-keyed, non-reversible lookup value and necessary verification state, not the readable national ID. Birth date and age may be retained for 18+ verification and age-based matching.
The initial release does not collect precise GPS location. Municipality is estimated from postcode and venue search uses a general area or public venues.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Create and operate the account; identity and 18+ checks | contract; legitimate interests in security and fraud prevention |
| Profile, introductions, dates and messages | contract |
| Matching from gender choice and answers | contract plus explicit consent under Article 9(2)(a) GDPR where data concerns sex life or sexual orientation |
| Optional Gemini advice | separate, informed and withdrawable consent before third-party disclosure |
| Abuse prevention, blocks, safety reports and investigations | legitimate interests in user and Service safety; legal duty or claim where applicable |
| Push notifications | contract or device consent, depending on the notification |
| Apple purchase verification and accounting | contract and legal obligation |
| Operations, diagnostics, security and web delivery | legitimate interests in a secure and reliable Service |
| Optional marketing email | consent, with an unsubscribe option |
Matching necessarily uses gender choice and answers. Explicit matching consent is therefore required to join matching, but not to keep an account, access Settings, withdraw consent, or exercise privacy rights. AI consent is separate, off by default, and never required for rule-based matching.
4. Matching, profiling and human review
A rule-based system compares predefined answers and preferences. If both people have active AI consent, Gemini may add an advisory score or rank public venue/time options.
A Papaya team member reviews and approves the final introduction. Users decide whether to accept and attend. No decision producing legal or similarly significant effects is made solely by automated means. You may request a general explanation of the main factors or raise a concern.
AI output is identified as advisory when shown to an administrator or user. We do not use facial recognition, emotion recognition, or biometric categorisation.
5. Data sent to Gemini
Matching sends only question keys, answer options, rankings and a baseline score for two people. Venue/time advice may send public venue names and addresses, ratings, date type and candidate times.
Names, national IDs, birth dates, profile IDs, emails, phone numbers, postcodes, photos, bios, messages and safety reports are not sent for these purposes. Requests use store:false, and Papaya does not enable optional log or dataset sharing for model training. Google may still process limited records for security, abuse prevention or legal obligations under its terms.
6. Recipients and processors
We disclose only what each purpose needs:
- Supabase for EU-region Auth, PostgreSQL, Storage, Realtime and Edge Functions;
- Kenni for electronic identity and 18+ verification;
- Apple for App Store, APNs and StoreKit;
- Google Maps Platform / Places for public venue search;
- Google Gemini API for optional AI advice;
- Cloudflare for DNS, TLS, security and delivery of
legal.single.isand the planned main site; - Brizy for temporary main-site hosting until the Cloudflare move is complete;
- Beehiiv for the optional mailing list and delivery information;
- advisers, insurers, courts or authorities where legally permitted or required.
We do not sell personal data. Processors must be bound to instructions, confidentiality, security, deletion and rights assistance.
7. International transfers
Some vendors or subprocessors may process data outside the EEA. Where applicable, we use an adequacy decision, EU Standard Contractual Clauses and supplementary safeguards following a transfer-risk assessment. Contact us for information about the current mechanism.
Gemini for EEA users is enabled only under Papaya’s paid Google Cloud service and applicable data-processing terms.
8. Retention
Normal operational limits are:
- account, profile and matching answers: while the account is active and processing remains necessary;
- AI matching scores: no more than 90 days and earlier on withdrawal;
- messages, read states, matching, dates and feedback: no more than 24 months under daily cleanup;
- closed safety reports: normally no more than 24 months after closure;
- push tokens: while the device/account remains active;
- consent history: while the account is active, then deleted with the account unless law or an existing legal claim requires narrow retention;
- operational, web-delivery and security logs: normally no more than 90 days unless an incident or legal duty requires otherwise;
- mailing-list data: while subscribed, with a minimal suppression record after unsubscribe where needed;
- purchase/accounting records: for the statutory period.
A documented legal hold may pause scheduled cleanup for specifically identified data needed for an active safety case, legal duty or claim. It is not a general archive. Current account deletion otherwise removes associated active data.
Backups expire on their schedule. After restoration, valid deletion requests are replayed before normal production resumes.
9. Controls and account deletion
In the app you can withdraw AI consent, withdraw sensitive-matching consent, pause matching, or delete the account. AI withdrawal deletes related AI scores. Sensitive-matching withdrawal stops new matching and also withdraws AI consent.
Account deletion revokes active sessions and removes the Auth account, profile, photos and associated data. Deletion is permanent. Narrow legal retention and temporary backups are the general exceptions. If an active, documented legal hold prevents automatic deletion, the member is directed to single@single.is; Papaya will then explain what is temporarily retained, why and when it will be reviewed, to the extent permitted by law.
10. Rights
Subject to legal conditions, you may request access, correction, deletion, restriction, portability, and object to legitimate-interest processing. You may withdraw consent at any time without affecting prior lawful processing.
Send requests to single@single.is. We may verify identity and generally respond within one month, with a lawful extension where necessary and notified.
You may complain to the Icelandic Data Protection Authority at personuvernd.is or another competent authority.
11. Security and incidents
Measures include HTTPS, RLS, private photo storage, column-level permissions, authenticated admin actions, a secret-keyed identity lookup, minimal AI payloads, and recording key consent/admin events. Staff access is role-limited and periodically reviewed.
No service is risk-free. We assess and document personal-data breaches, notify the authority within the legal period where risk is likely, and notify affected people without undue delay where high risk is likely.
12. Children and changes
The Service is 18+ only. Accounts connected to minors are closed and data removed as law and safety permit.
We update this Policy when the Service, processing or law changes. Material changes are notified in advance where required, and fresh consent is requested for new sensitive-data processing or AI disclosure where required.