Draft: this wording is still being reviewed, and a few business details are yet to be filled in.
Privacy Policy
Last updated 2026-10-01
This explains what MakeItLit! collects, why, who it’s shared with, how long it’s kept, and what you can do about it. [COMPANY LEGAL NAME] is responsible for your data. Contact: privacy@makeitlit.app.
What we collect
- Account: username, email, password (handled by our sign-in provider, never stored in plain text), birth date and gender.
- Profile: photos, videos, prompts and your answers to the app’s questions. The “Looking for” and bedroom answers are private: nobody else ever sees them. With a plan that includes it, two mutuals see a general fit level, never each other’s answers.
- Approximate location, if you allow it: rounded to about 1 km. It is only used to work out distances, and nobody ever sees it. The distance others see is rough on purpose: measured from a point up to 1.5 miles from you, so it can’t be used to find where you are.
- Activity: the people you Keep or Vanish, mutuals, messages (date invites too: a place and a time), games of Find Me you play in a chat (the board and your moves), photos you send in chat, High Key selfies, Flickers (a few frames of a moving selfie) and the voice bits you send, reports and blocks.
- Feed video views: when you watch someone’s feed video for a few seconds, it counts as a view. Its creator sees how many views it got, never who watched, with one exception: an Afterlife creator sees the names of people who had liked them or are their mutuals and watched.
- Verification selfies, only if you choose to verify and agree first: a few quick selfies doing moves we ask for (turning your head, smiling, opening your mouth or closing your eyes). Amazon Web Services checks each move and compares the face in them with the face in your main photo, which measures facial features (biometric data). We don’t keep those measurements, and the selfies are deleted as soon as the check is done. They’re used for that check only: never for advertising, never sold. We keep a record that you agreed, and when.
- Device and app: your notification token and settings, and basic technical logs.
- An activity log, kept 7 days: the time, IP address and app details of each request your phone makes to our servers, and the approximate locations it sends (about 1 km). It’s there so a safety report, or someone going missing, can still be looked into days later.
- A code made from your phone’s device identifier (never the identifier itself), to stop fake and duplicate accounts, invite abuse and banned accounts coming back. Deleted with your account.
- Your mobile number, if you verify it for free features (invite rewards, and free features where the app is new): Amazon Web Services texts you a code and checks what kind of number it is (mobile, landline or internet). We keep only a code made from the number (a keyed hash), never the number itself, so one number can’t unlock the free features on several accounts.
- Pronouns, if you add them: shown on your profile.
- Compatibility, if you add it: how you describe your looks (build, hair, eyes, tattoos, style), your love language, social energy, and movie and music taste; your religion and whether your faith matters to you; your background; and what you’re drawn to (your type) and the backgrounds you’d like to see first. Only what you tell us: nothing is worked out from your photos. Your type, your background, those preferences and whether your faith matters to you are never shown to anyone.
- Invites: the code you joined with, if any, and how many people joined with yours. Whoever invited you sees only their count, never who joined.
- Feedback you send us from the app: your message, which screen it came from and the app version, with your username so we can follow up. It is used to improve the app.
- Subscriptions: your plan, its renewal dates, what the store charged you, and the terms shown above the buy button when you subscribed, word for word (the record of what you agreed to). The store handles payment: we never see your card.
- Concerns you send about a feature (How it works, then “Something’s not right”): what you wrote, which feature, any law or case you named and the app version, with your account so we can answer you. Each one starts a review of that feature.
- Open book, if you fill it in: the topics you’re happy to be asked about. Only your mutuals see it, and it never says anything about you beyond which topics are welcome.
- If you ask us to remove an image (even without an account): your name, email, typed signature and what you tell us about it.
- If you use a form that needs no sign-in (removing an image, asking for a review of a suspended account): a code made from your internet address, never the address itself, counting how often it’s used, so the forms can’t be flooded. Deleted after 30 days at most.
- Signals for spotting bots and fake accounts: the timing of your actions, where a hold starts on the screen and how far your finger moves, and how long a message took to type. For messages, we keep only a fingerprint (a hash), never the text.
- Safety alerts: if an account that sent you a message is banned for fraud or a false identity, the alert we send you about it, and when you saw it.
How we use it
- To run the app: showing your profile, suggesting people, delivering messages and photos, and notifying you.
- To order your deck: people who fit what you asked for (your type, with Lit+; backgrounds you’d like to see first; the same faith, if it matters to you) come first, and nobody is hidden for it. On Lit Afterlife, members on a plan come first too. We work out compatibility scores from what both people filled in; you can ask us for yours (privacy@makeitlit.app).
- To keep people safe: automated checks on photos, videos and some messages for nudity, violence, hate and abuse; spotting bots and scams; and handling reports.
- To provide paid features, and to follow the law.
We do not sell your personal information. We do not use it for targeted advertising. We don’t use it to train large language models or other AI, and we don’t sell or give it to anyone for that.
Ads: on the free plan, MakeItLit! shows ads from Google (AdMob), between videos in the feed and when you choose to watch one for a reward. They’re never personalized: we don’t give Google your profile, matches, messages or anything else about you. Google’s ad software on your phone collects what it needs to show and count ads and to stop fraud (your phone’s advertising ID, an approximate location from its internet address, and which ads you see and tap), under Google’s own privacy policy. Where the law requires it, you’re asked first. Paid plans have no ads in the feed.
Sensitive information
Some of what you tell us is sensitive information: it can reveal your sex life, sexual orientation, gender identity (including being non-binary or transgender), religion or health. That’s your gender and who you want to see, and, only if you add them, the private bedroom answers, “Faith” among your values and some Open book topics (faith, health, mental health, gender identity, sexuality, intimacy, sobriety). We ask for your OK on its own before using it, use it only to show you to the right people and for the features you add it to, and never sell it, use it for ads, or use it to train AI.
You can take that OK back any time in Settings, then Sensitive information: turning off the optional answers deletes them, and taking back the rest deletes your gender and who you want to see, which takes you out of Discover until you agree again. We act on it at once (the law allows 15 days).
Biometric data: our Biometric Data Policy explains what selfie verification measures, how long anything is kept and how it’s destroyed. Washington and Nevada residents: our Consumer Health Data Privacy Policy covers the data those states treat as health data.
Who we share it with
- Other members: your public profile. They see your distance only as a number of miles, and an “active” label only if you both allow it.
- Compatibility, if you add it: your religion, to everyone; your looks, love language and social energy, to members on Lit+ or Lit Afterlife; your movie and music taste, to Lit Afterlife members; whether you’re each other’s type, to members on those plans, never what your type is. Your plan only if you turn on “Show my plan on my profile”.
- Friends you add with your friend code: your name and face; in a Squad Meet, your age and likes only if you turn them on. A friend can suggest someone to you from the feed: you see which friend suggested them, the person suggested isn’t told, and a suggestion is kept 30 days. A friend can also give you a heads-up about someone (a reason, and maybe a short note): you see it on their card, the person isn’t told, and it’s kept 90 days. When several different people give heads-ups about the same person, our safety team sees how many and why, but never the notes, and nothing happens to that person unless a moderator decides.
- Group chats with friends: what you write goes to the friends in that chat, and fades after 90 days (deleting your account removes it sooner). Someone shared into one shows only their first name, first photo and age, fades after 7 days, is never shown to a member they’ve blocked, and isn’t told. You can turn off being shared this way in Settings, and cards of you already shared go too. Members can vote Keep or Vanish on a shared card: the chat sees the counts, never who voted what, and the person never sees any of it.
- The Fine Print, with a mutual: the lines you pick, and up to two you write yourself, go to that mutual. Lines you write get the same automated check as a message. To improve the suggested lines, we count how often each one is picked, and how many people write the same line of their own, keeping that line’s words for 180 days, but never who wrote it. Deleting your account removes your Fine Print from your mutual’s side too.
- Feed videos you send to a mutual or a Council: we keep a record of who sent which video to whom for 30 days, to spot videos passed around for views or as ads (for example by several accounts on one phone). A video that looks like that is marked for everyone who got it, and our team is told. On the free plan, a video sent to you can be watched for 3 days.
- Service providers that process data for us under contract: Amazon Web Services (hosting, storage, automated image and text checks, and verification texts), Expo (delivering notifications), and Apple and Google (app stores, payments and notifications).
- GIPHY, for GIFs in chat: when you search for a GIF, your phone sends what you type straight to GIPHY, and GIPHY sees your phone’s internet address, as any website does. GIFs, including ones sent to you, load from GIPHY’s servers the same way. We don’t send GIPHY your name, your account or anything else about you, and we don’t keep your searches. GIPHY’s own privacy policy covers what it does with them. Results are rated PG-13 at most.
- People an account messaged, if we ban it for fraud or a false identity (several states’ laws require this): its name, username and main photo, and when it last messaged them. Nothing else about it.
- Law enforcement and authorities, when valid legal process requires it or someone is in danger. We report apparent child sexual abuse material to the National Center for Missing & Exploited Children, as US law requires.
- When someone may be at risk, or the law requires it (for example, a request to preserve records), we keep a copy of the account’s information, including its messages, photos and reports, for the authorities. We share it only as the law allows or requires.
- A buyer or successor, if the business is sold, under this policy.
How long we keep it
- Your account and profile: until you delete your account. Deleting it removes your profile, photos, videos, mutuals and conversations from the app at once, and we email the address on your account to confirm it (your certificate of deletion); an encrypted safety copy is kept for 7 days, then erased. It’s encrypted with a key of our own, and opening it takes several logged steps: a case opened by our safety team (two-step sign-in), for a safety report or a lawful request, with every access recorded.
- A feed video you delete: out of the feed, your profile and chats at once, kept 30 days so you can restore it, then deleted for good.
- Messages you unsend: gone for both of you at once; an encrypted safety copy is kept for 7 days, then erased. It’s encrypted with a key of our own, and opening it takes several logged steps: a case opened by our safety team (two-step sign-in), for a safety report or a lawful request, with every access recorded.
- Chat photos: normal photos for 30 days. Private photos are deleted once they’ve been opened, or after 2 days if they aren’t. For each private or blurred photo, and any photo blocked by our checks, an encrypted safety copy is kept for 7 days, then erased. It’s encrypted with a key of our own, and opening it takes several logged steps: a case opened by our safety team (two-step sign-in), for a safety report or a lawful request, with every access recorded.
- High Key date photos, Flickers and voice bits (voice dates too): deleted when the date ends, and within a day at most. Every photo and Flicker frame you send by hand is checked for explicit content before it’s delivered. Voice bits are short recordings you choose to send; nobody listens to them unless they’re reported. Because screenshots are blocked during a date, an encrypted safety copy is kept for 7 days, then erased. It’s encrypted with a key of our own, and opening it takes several logged steps: a case opened by our safety team (two-step sign-in), for a safety report or a lawful request, with every access recorded. If you’re reported, your selfies, Flickers and voice bits from that date are kept with the report (180 days).
- Reported content and moderation records: until the report is resolved, and longer when the law requires (for example, when a report is made to authorities). Decisions, and what you write when you ask for a review of one, stay with the moderation record.
- Photos reported in chats: kept for our safety team for 180 days, so a decision can be reviewed if you ask, then deleted.
- Videos our checks refuse: taken down at once; the video itself is kept encrypted for our safety team for 180 days, then deleted.
- A new profile photo: private until our check passes, and only then shown. One that is never checked is deleted within 1 day.
- Information preserved for the authorities: until the matter is over and no legal hold remains, even if the account is deleted.
- Requests to remove an intimate image: the request and what we did about it are kept as a record, and we email the person who asked what we did, or why not. Removed images are kept encrypted where only our safety team can reach them, and deleted after 90 days, or after a year when we’ve reported them to the National Center for Missing & Exploited Children, as the law requires. A fingerprint of each removed file (a code worked out from its exact bytes, which can’t be turned back into the image) is kept with the record, so the same file can’t be uploaded again.
- Games of Find Me: kept with the chat, and deleted 30 days after the last move (or with the chat, if an account is deleted).
- Face measurements from verification: not kept. The selfies are deleted as soon as the check is done (ones that are never checked, within 1 day).
- Your mobile number: not kept. The code made from it stays with your account, and for 90 days after you delete it, so the number can’t start the free features over on a new account.
- An account we banned, if it’s deleted: its sign-in record (username and email) is kept switched off, so it can’t simply join again, and the codes made from its phones and mobile number are kept 3 years. An account deleted while hidden for review: the codes made from its phones, 90 days. Nothing else is kept.
- Fraud alerts: the alert in your app, with your account. Our record of who was told, when and how: 3 years.
- Subscription records (the terms you agreed to, and the purchase): 3 years, or 1 year after the subscription ends, whichever is longer, even if you delete your account sooner, as the automatic-renewal laws ask.
- Concerns about a feature: 3 years, with our review and answer, even if you delete your account sooner (it’s the record of how we handled it).
- Technical logs and the activity log: 7 days. Daily usage counters: 90 days. Feed video view counts: 90 days.
Your choices and rights
- See and download your data: Edit profile, then Download my data.
- Correct it: edit your profile at any time.
- Delete it: Edit profile, then Delete account. Without the app: makeitlit.app/delete-account.
- Turn off notifications, location or private photos, or hide when you’re active, in settings.
Depending on where you live (for example Connecticut, Colorado, Virginia, Texas or Oregon), you also have the right to confirm whether we process your data and see it, to correct it, to delete it, to get a copy you can take elsewhere, and to opt out of targeted advertising, the sale of your data, and profiling that has legal or similarly significant effects. We do none of those three. To ask, write to privacy@makeitlit.app from the email address on your account. We answer within 45 days (if we need up to 45 more, we tell you why within the first 45), for free once a year.
If we turn down a request, you can appeal: reply to our answer, or write to privacy@makeitlit.app with “Appeal” in the subject. Within 45 days we tell you in writing what we did and why. If we turn down your appeal, you can complain to your state’s attorney general. We won’t treat you differently for using any of these rights.
Age
MakeItLit! is for adults only. We delete accounts we find belong to anyone under 18.
Security and changes
We use encryption in transit, access controls and limited retention to protect your data. No system is perfectly secure.
If we change this policy in a meaningful way, the app will tell you before the change applies.