Privacy Policy
Effective date: 16 May 2025 · Last updated: 2 September 2026
This Privacy Policy explains how Filltr (“we”, “our”, or “us”) collects, uses, stores, and protects your personal data when you use the Filltr mobile application and related services. Filltr is operated by Filltr UG (haftungsbeschränkt), a company registered in Berlin, Germany, and is subject to the EU General Data Protection Regulation (GDPR).
Data controller: Filltr UG (haftungsbeschränkt), c/o Taras Nikolenko, Wiclefstraße 65, 10551 Berlin, Germany (Amtsgericht Charlottenburg, HRB 291045 B) — privacy@filltr.de
1. Age Restriction
Filltr is an adult dating platform intended exclusively for users who are 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If we become aware that an account belongs to a minor, we will immediately terminate that account and delete all associated data. By creating an account, you confirm that you are at least 18 years old.
2. Data We Collect
2.1 Account & Profile Data
When you register, we collect your email address and create a unique user ID. Your profile may include a display name, date of birth (to verify age), pronouns, gender identity, sexual orientation, relationship goals, community archetypes you select for yourself (“I am”) and the archetypes you indicate interest in (“Into”), a short bio, hashtags/interests, and up to three photos. This information is visible to other users on the platform according to your privacy settings.
2.2 Photos & Media
Profile photos are uploaded by you and stored securely on our own servers in the EU (Germany). Uploaded images are automatically scanned by our self-hosted image-moderation system — running on our own infrastructure, so photos never leave our servers for scanning — for illegal content, nudity violations, and other prohibited material before the image is published. The scan result (safe/flagged) is stored internally for moderation. Images are not used to train third-party AI models.
Expiring photos (a Pro feature) are media shared inside chats. They are stored for the duration specified by the sender and then deleted from our servers.
2.3 Messages & Communications
Chat messages between matched users are stored in our self-hosted database on our own EU servers (Germany) to deliver the service. Messages include text content, timestamps, read receipts, and typing indicators. We may review flagged or reported conversations as part of our moderation process. Messages from deleted accounts are retained for a limited period for safety and legal compliance before being purged.
2.4 Location & Distance
Filltr uses your device’s location to show you nearby users and calculate approximate distances. We store your last known coordinates in your user profile and use them solely for proximity matching. We do not sell or share your precise location with advertisers. Other users see only an approximate distance (e.g., “2 km away”), never your exact coordinates. You can revoke location permission at any time via your device settings.
Map displays in the app — the location picker and the previews of locations shared in chat — are rendered by Google Maps (Google Maps SDK for Android). When a map is shown, Google receives the map area being displayed and your IP address, as with any use of Google Maps; see Google’s privacy policy. We do not send your account identifier to Google Maps, and your stored profile location is never displayed on a map to other users.
2.5 Subscriptions & Payments
Premium subscriptions (Filltr Pro — Monthly and Filltr Pro — Yearly) are processed entirely through Google Play Billing. We never see or store your payment card details. We receive from Google a purchase token, product ID, subscription period start/end dates, auto-renewal status, and acknowledgement status. This data is stored in our database to determine your entitlement and for legal/tax record-keeping as required by EU law. Subscription management (upgrade, cancel, refund) is handled through the Google Play subscriptions page.
2.6 Crash Reports (no usage analytics)
The app does not run usage analytics: no third-party analytics SDK is active, and we do not track screens visited, actions taken or session duration. What we do collect are crash reports, processed by Sentry (sentry.io, EU region) so we can fix bugs. A crash report contains the technical stack trace, app and OS version, device model and recent technical log lines. Before it leaves your device we strip identity: no account ID, no email, no location, no message or photo content, and no advertising identifier. Crash reporting is on by default and can be switched off at any time in Settings → Privacy → “Send crash reports”. You can find Sentry’s privacy policy at sentry.io/privacy.
2.7 Profile Views
When you view another user’s profile, a view event is recorded so they can see who visited their profile. You can enable Incognito Mode (Pro feature) to browse anonymously — your view will not be recorded while incognito is active.
2.8 Intention Mode
If you activate Gentle or Direct intention mode, your selected mode is stored on your profile and is visible to other users who have the same or a compatible mode active. This data is cleared when you deactivate the mode.
2.9 Reports & Moderation Data
When you report a user or content, we collect the report reason, any optional description you provide, and the reported content or user ID. This data is stored in our moderation system and reviewed by our admin team. False or malicious reports may result in action against the reporting account.
3. How We Use Your Data
- To create and maintain your account and authenticate you.
- To show your profile to other users for dating and connection purposes.
- To deliver and improve matching, browsing, and communication features.
- To process and validate subscription entitlements via Google Play.
- To detect and remove prohibited content via automated image scanning that runs on our own servers.
- To investigate reports, enforce our Community Guidelines, and keep the platform safe.
- To monitor and fix crashes and performance issues via Sentry.
- To comply with legal obligations, including tax, fraud prevention, and law enforcement requests.
- To send transactional notifications (e.g., new message alerts) — never marketing without consent.
Legal bases (GDPR Art. 6): Contract performance (to provide the service), Legitimate interests (safety, fraud prevention, crash monitoring), Legal obligation (tax, compliance), and Consent (where indicated at collection).
4. Third-Party Services
| Service | Purpose | Location |
|---|---|---|
| Hetzner | Server hosting for our self-managed backend — database & file storage | Germany |
| Zoho Mail | Transactional & support email delivery | Global (Zoho Corporation) |
| Google Play Billing | Subscription payments | Global (Google) |
| Sentry | Crash reporting & performance (opt-in, off by default) | EU (Sentry GmbH) |
| Firebase FCM | Push notifications | Global (Google) |
| Google Sign-In | Optional OAuth login | Global (Google) |
| GIPHY | GIF search & delivery in chat (only when you open the GIF picker or view a GIF) | USA (Giphy, Inc.) |
AI processing is self-hosted: the support assistant on our website and our automated image moderation both run on Filltr's own servers in Germany. Your messages to the assistant and your uploaded photos are never sent to third-party AI providers.
GIFs in chat: when you open the GIF picker, your search terms are sent directly from your device to GIPHY; when you view a GIF in a chat, your device loads it directly from GIPHY's content delivery network. In both cases GIPHY receives your IP address — as with loading any web image — but never your Filltr account identifier; see GIPHY's Privacy Policy.
Where transfers outside the EEA occur (e.g., Google, Zoho, or GIPHY services), they are covered by Standard Contractual Clauses (SCCs) or an adequacy decision.
5. Data Sharing
We do not sell your personal data. We share data only in the following cases:
- With other users — your profile, photos, distance, and intention mode as described in Section 2.
- With our service providers — listed in Section 4, strictly to deliver the service under data processing agreements.
- For legal compliance — if required by law, court order, or to protect the safety of users or the public.
- Business transfers — in the event of a merger, acquisition, or sale of assets, users will be notified and their rights protected.
6. Data Retention
- Active account data — retained as long as your account exists.
- Deleted accounts — profile data is deleted within 30 days of account deletion. Some data (e.g., moderation records, subscription billing records) may be retained longer for legal compliance.
- Messages — retained while both parties’ accounts exist. If one party deletes their account, their messages are anonymised or deleted within 30 days.
- Crash logs (Sentry) — retained for 90 days.
- Subscription billing records — retained for 10 years per German commercial and tax law (HGB § 257, AO § 147).
- Moderation records — retained for up to 3 years to address appeals and recurring violations.
7. Your Rights (GDPR)
As an EU data subject, you have the following rights:
- Access — request a copy of the data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your personal data (“right to be forgotten”). You can delete your account in-app via Settings → Delete Account.
- Portability — receive your data in a structured, machine-readable format (JSON/CSV). Email us at privacy@filltr.de to request a data export.
- Restriction — ask us to pause processing of your data in certain circumstances.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, you can withdraw it at any time.
To exercise any right, email privacy@filltr.de. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority — in Germany: BfDI (bfdi.bund.de).
8. Account Deletion & Data Export
You can delete your account at any time from Settings → Delete Account inside the app. Deletion is permanent and cannot be undone. We will remove your profile, photos, and personal data within 30 days, subject to legal retention requirements noted in Section 6.
To request a copy of your data before deletion, email privacy@filltr.de. We will provide an export within 30 days of your request.
For data deletion requests not initiated through the app, visit our Data Deletion Request page.
9. Moderation & Admin Review
Our admin team may review profile content, photos, and reported messages to enforce our Community Guidelines. This access is limited to trained staff, logged for audit purposes, and never used for commercial purposes. Automated image scanning (self-hosted, on our own servers) provides a first-pass review of all uploaded photos. Flagged content is queued for human review before any enforcement action.
If your account is actioned (warned, hidden, or banned), you will be notified where reasonably practicable. Appeals can be submitted via support@filltr.de.
10. Security
We implement industry-standard security measures including TLS encryption in transit, row-level security (RLS) policies in our database, JWT-based authentication, and regular dependency audits. No system is perfectly secure — if you believe your account has been compromised, contact support@filltr.de immediately.
11. Children’s Privacy
Filltr is strictly for adults (18+). We do not knowingly collect data from children. If you believe a minor has created an account, report it to safety@filltr.de and we will act immediately.
12. Changes to This Policy
We may update this Privacy Policy to reflect product changes, new legal requirements, or improved transparency. Material changes will be communicated via in-app notification and by updating the effective date above. Continued use of Filltr after the update constitutes acceptance of the revised policy.
13. Contact
For privacy questions, data requests, or to exercise your GDPR rights:
- Email: privacy@filltr.de
- Legal: legal@filltr.de
We respond to all data requests within 30 days.