Effective date: 5 September 2026
foaf is built on a simple premise: to introduce you to someone worth meeting, we have to know you first. That means you will tell us more about yourself here than you would on most apps — and it means we owe you more in return.
This policy explains, in plain language, what we collect, why we collect it, what our AI does with it, and what control you have. We have tried to avoid legal padding. Where we use a legal term, we explain it.
foaf is a digital product operated by:
HAYDAR SAS Société par actions simplifiée à associé unique 47 rue Vivienne, 75002 Paris, France SIREN / RCS: 104 899 992 R.C.S. Paris EUID: FR7501.104899992
HAYDAR SAS is the data controller for the personal data described in this policy. That means we decide what data is collected and why, and we are legally accountable for it under Regulation (EU) 2016/679 (the "GDPR") and the French Data Protection Act (Loi Informatique et Libertés).
For privacy questions: privacy@foaf.app For general support: hello@foaf.app
This policy applies to foaf.app and to any related service we operate under the foaf name (together, the "Service").
It does not apply to third-party websites or services you may reach through links we provide. Those have their own policies.
Account information. To create an account you give us your email address. We do not use passwords — we send a one-time code to your email each time you sign in. Each new code cancels any earlier one. Because there is no password, access to your email inbox is access to your foaf account; keep it secure.
Onboarding conversation. foaf gets to know you through a conversation. In the course of that conversation you may tell us:
Photographs. At least one clear photograph of your face is required before we can suggest anyone to you. You may add more.
Payment information. If you subscribe, our payment processor collects your card details. We never see or store your full card number.
Support correspondence. If you contact us, we keep what you send.
Your messages. We process your conversations with foaf and your conversations with other members in shared chats.
Your responses to suggestions. Each day we may show you a small number of profiles. Your answer to each — and any reason you give — is recorded.
Derived scores. From your activity we calculate values that are never shown to you or to anyone else:
Engagement patterns. How often you use the Service, how long your sessions are, when you go quiet.
Reports. If you report another member, or another member reports you, we keep a record.
Other members may provide information about you — for example when they respond to your profile or submit a report about you.
Under the GDPR we must have a lawful basis for every use of your data. Here is each purpose and its basis.
Some of what you tell foaf may reveal your sexual orientation, religious or philosophical beliefs, or health. We process this on the basis of your explicit consent, and on that basis alone. See section 6.
We do not treat account creation as consent. Consent under the GDPR must be a specific, informed and unambiguous act, and we ask for it separately, before any special category data is processed.
Our legitimate interest is protecting members from harm. We have weighed this against your privacy and consider it proportionate: the alternative is a platform where abuse goes unchecked.
Where we can do this with aggregated or anonymised data, we do.
We send promotional email only if you opt in. You can withdraw at any time, and every such email has an unsubscribe link. Service messages — a code to sign in, a notice that someone is waiting to meet you, a receipt — are not marketing and are sent under basis A.
foaf is an artificial intelligence. It is not a person. We tell you this before your first conversation begins, in accordance with Article 50 of Regulation (EU) 2024/1689 (the "AI Act"). Every member is told the same thing. No member of foaf is ever presented to you as a human being when it is not one.
foaf reads what you write and builds a structured understanding of you: your personality, your circumstances, your preferences, the way you communicate. It updates this quietly as you talk. It uses that understanding to decide:
It also participates in shared conversations — opening them, occasionally contributing, and returning if a member asks it to.
As described in section 3.2, foaf calculates a compatibility estimate, an attractiveness level and a match outcome score. These are internal. They are not published on your profile, not visible to other members, and not visible to you.
We keep the attractiveness level private deliberately. Showing people a number representing how attractive others found them would do harm, and it is not information you need.
Article 22 of the GDPR gives you the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you.
Our view is that suggesting a person you might like to meet does not reach that threshold. Nevertheless, we do not want you to have to take our word for it. If you believe an automated decision has affected you unfairly — for example, if you believe you are being shown to very few people — write to privacy@foaf.app. A human being at HAYDAR SAS will review it, explain what we find, and correct it where correction is warranted.
We do not use your data for automated decisions about employment, credit, insurance, housing, or anything else with legal consequences.
We use your data to operate and improve foaf. We do not sell your conversations, and we do not license them to third parties to train their own models. If we ever wish to use member conversations to train a model in a way that goes beyond operating this Service, we will ask you first.
Article 9 of the GDPR protects certain categories of data more strictly: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data, health data, and data concerning a person's sex life or sexual orientation.
foaf's conversation may touch on several of these. If you tell foaf that you are looking for a man, or that you observe a religion, or that you do not drink for health reasons, that is special category data.
We process it on the basis of your explicit consent under Article 9(2)(a). You give that consent by choosing to share it. You are not required to answer any question foaf asks — though the less you share, the harder it is for foaf to find someone right for you.
You may withdraw this consent at any time by writing to privacy@foaf.app. We will delete the relevant data. Depending on what you withdraw, we may no longer be able to suggest matches, in which case we will tell you.
We do not use facial recognition, and we do not extract biometric data from the photographs you upload.
We do not sell your personal data. We do not share it with advertisers, data brokers, or anyone who wants it for their own purposes.
When foaf introduces you to someone, it shares a short written description of you, drawn from your profile and your conversations, together with your photograph. What appears in that description is limited to what is appropriate to share with a stranger who may become a friend.
Never shared: your email address, your exact age if you have asked us to keep it approximate, your financial details, your internal scores, anything you have asked foaf to keep private, and any photograph flagged as inappropriate.
If you share a social media link with foaf and it is passed on, we will say plainly that we cannot verify it.
Once a shared conversation opens, whatever you choose to say in it is between you and the other member. Be thoughtful about what you disclose.
We use third parties to run the Service. Each acts as a processor under Article 28 of the GDPR — they may only use your data on our instructions, under a written contract:
| Purpose | What they handle |
|---|---|
| Cloud hosting and databases | All service data |
| AI model providers | Conversation content and profile notes, for generating foaf's responses and assessments |
| Payment processing | Card details, billing information |
| Email delivery | Email address, message content |
| Error monitoring and analytics | Technical and usage data |
We select providers on their security and privacy record, and we review them.
We want to be explicit about one of these: your conversations with foaf are sent to a third-party AI model provider in order to generate foaf's replies. That provider acts as our processor, is contractually barred from using your data for its own purposes, and does not use it to train its models.
We may disclose data where we are legally obliged to, or where it is necessary to prevent serious harm to a person. Where the law permits us to tell you, we will.
If HAYDAR SAS is sold, merged or restructured, member data may transfer to the acquiring entity. We will notify you beforehand and your rights under this policy will continue to apply.
We operate from France. Some of our service providers process data outside the European Economic Area.
Where that happens, we ensure protection through one of the mechanisms in Chapter V of the GDPR:
To ask which providers process data outside the EEA and under which safeguard, write to privacy@foaf.app.
We use cookies that are strictly necessary to operate the Service — keeping you signed in, remembering your language, protecting against abuse. These do not require your consent.
For anything beyond that, we ask first, through a banner that lets you refuse as easily as accept. Refusing non-essential cookies does not limit your use of the Service.
You can also manage cookies in your browser settings.
| Data | Retention |
|---|---|
| Account and profile data | While your account is active |
| Conversations with foaf | While your account is active |
| Shared conversations with members | While your account is active |
| Photographs | While your account is active, or until you delete them |
| Derived scores | While your account is active |
| Records of reports and enforcement | 3 years from the decision |
| Content removed for illegality | As required to cooperate with authorities |
| Payment and transaction records | 10 years (French Commercial Code, Art. L123-22) |
| Server logs | 12 months |
| Consent records | 5 years |
| Anonymised, aggregated statistics | Indefinitely — no longer personal data |
Inactive accounts. If you do not sign in for two years, we delete your account and notify you at your registered email address beforehand.
After deletion. When you delete your account we remove your profile and photographs immediately. We keep limited data for thirty days to guard against accidental deletion and to complete any open safety investigation, after which it is erased — except for the records listed above that we are required to keep.
Resetting your conversation. You can reset your foaf conversation from the menu at any time. This deletes your conversations, your suggestions, your matches and the profile foaf has built, and starts you over from the beginning. It does not delete your account.
Under the GDPR you have the following rights. All of them are free to exercise.
Access (Art. 15). Ask for a copy of the data we hold about you, including the profile foaf has built from your conversations.
Rectification (Art. 16). Correct anything inaccurate. You can also simply tell foaf — it will update its notes.
Erasure (Art. 17). Ask us to delete your data. You can do this yourself from the menu.
Restriction (Art. 18). Ask us to stop processing while a dispute is resolved.
Portability (Art. 20). Receive your data in a structured, machine-readable format.
Objection (Art. 21). Object to processing based on legitimate interests. For direct marketing, your objection is absolute and immediate.
Human review (Art. 22). As described in section 5.
Withdraw consent (Art. 7(3)). Where we rely on consent, withdraw it at any time. This does not affect processing that already took place.
Write to privacy@foaf.app. We respond within one month. If a request is complex we may extend by two further months and will tell you why within the first month.
We may ask you to confirm your identity. We may decline a request that is manifestly unfounded or excessive, or that would reveal another member's personal data — for instance, a request for a copy of messages another member sent you.
If you are unhappy with how we have handled your data, tell us first — we would rather fix it. You also have the right to complain to a supervisory authority. In France:
CNIL — Commission Nationale de l'Informatique et des Libertés 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 www.cnil.fr
If you live in another EEA country you may complain to your own national authority.
We protect your data with encryption in transit and at rest, access controls limiting staff access to what their role requires, sign-in by one-time code rather than reusable passwords, logging and monitoring, and regular review of our providers.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the CNIL within seventy-two hours and, where the risk is high, notify you without undue delay.
foaf is for adults. You must be 18 or older to use it.
We do not knowingly collect data from anyone under 18. If we learn that a member is under 18 we delete the account and the data immediately.
If you believe a minor is using the Service, report it through the app or write to hello@foaf.app.
We may update this policy. If a change materially affects your rights or how we use your data, we will notify you by email or in the app at least fourteen days before it takes effect. Continuing to use the Service after that date means you accept the updated policy. If you do not, you may delete your account.
Minor changes — a corrected address, a clearer sentence — take effect on publication.
The effective date is at the top of this page.
Privacy: privacy@foaf.app Support: hello@foaf.app
By post: HAYDAR SAS — foaf 47 rue Vivienne 75002 Paris France
Supervisory authority: CNIL, www.cnil.fr
HAYDAR SAS · SIREN 104 899 992 R.C.S. Paris · 47 rue Vivienne, 75002 Paris, France