Privacy Policy

Effective date: 5 September 2026


Our commitment

foaf is built on a simple premise: to introduce you to someone worth meeting, we have to know you first. That means you will tell us more about yourself here than you would on most apps — and it means we owe you more in return.

This policy explains, in plain language, what we collect, why we collect it, what our AI does with it, and what control you have. We have tried to avoid legal padding. Where we use a legal term, we explain it.


Table of contents

  1. Who we are
  2. Scope of this policy
  3. Information we collect
  4. How we use your information and our legal bases
  5. Artificial intelligence, profiling and automated decisions
  6. Special category data
  7. How we share your information
  8. International transfers
  9. Cookies and similar technologies
  10. How long we keep your information
  11. Your rights
  12. Security
  13. Age requirement
  14. Changes to this policy
  15. How to contact us

1. Who we are

foaf is a digital product operated by:

HAYDAR SAS Société par actions simplifiée à associé unique 47 rue Vivienne, 75002 Paris, France SIREN / RCS: 104 899 992 R.C.S. Paris EUID: FR7501.104899992

HAYDAR SAS is the data controller for the personal data described in this policy. That means we decide what data is collected and why, and we are legally accountable for it under Regulation (EU) 2016/679 (the "GDPR") and the French Data Protection Act (Loi Informatique et Libertés).

For privacy questions: privacy@foaf.app For general support: hello@foaf.app


2. Scope of this policy

This policy applies to foaf.app and to any related service we operate under the foaf name (together, the "Service").

It does not apply to third-party websites or services you may reach through links we provide. Those have their own policies.


3. Information we collect

3.1 Information you give us directly

Account information. To create an account you give us your email address. We do not use passwords — we send a one-time code to your email each time you sign in. Each new code cancels any earlier one. Because there is no password, access to your email inbox is access to your foaf account; keep it secure.

Onboarding conversation. foaf gets to know you through a conversation. In the course of that conversation you may tell us:

  • your name and how you would like to be addressed
  • your gender
  • your age and star sign
  • the city and country where you live
  • your occupation and professional background
  • your education
  • your financial situation and living arrangements, in general terms
  • your lifestyle and habits, including whether you smoke, drink or exercise
  • your interests and how you spend your time
  • the languages you speak
  • your relationship status and history
  • what you are looking for and what kind of person you hope to meet
  • your dealbreakers
  • links to your social media profiles, if you choose to share them

Photographs. At least one clear photograph of your face is required before we can suggest anyone to you. You may add more.

Payment information. If you subscribe, our payment processor collects your card details. We never see or store your full card number.

Support correspondence. If you contact us, we keep what you send.

3.2 Information generated by your use of the Service

Your messages. We process your conversations with foaf and your conversations with other members in shared chats.

Your responses to suggestions. Each day we may show you a small number of profiles. Your answer to each — and any reason you give — is recorded.

Derived scores. From your activity we calculate values that are never shown to you or to anyone else:

  • a compatibility estimate between your profile and another member's
  • an attractiveness level, derived from how members have responded to your profile over the preceding sixty days
  • a match outcome score, calculated twenty-four hours after a shared conversation opens, based on whether and how much the two of you wrote

Engagement patterns. How often you use the Service, how long your sessions are, when you go quiet.

Reports. If you report another member, or another member reports you, we keep a record.

3.3 Technical information

  • IP address and the approximate location it implies
  • device type, operating system and browser
  • server logs and diagnostic data
  • data collected through cookies (see section 9)

3.4 Information from others

Other members may provide information about you — for example when they respond to your profile or submit a report about you.


4. How we use your information and our legal bases

Under the GDPR we must have a lawful basis for every use of your data. Here is each purpose and its basis.

A. Running the Service — performance of a contract, Art. 6(1)(b)

  • creating and maintaining your account
  • letting foaf converse with you and build your profile
  • calculating compatibility and selecting who to suggest
  • opening shared conversations between matched members
  • delivering the features of your plan
  • handling payments and subscriptions
  • answering support requests

B. Sensitive details in your profile — explicit consent, Art. 9(2)(a)

Some of what you tell foaf may reveal your sexual orientation, religious or philosophical beliefs, or health. We process this on the basis of your explicit consent, and on that basis alone. See section 6.

We do not treat account creation as consent. Consent under the GDPR must be a specific, informed and unambiguous act, and we ask for it separately, before any special category data is processed.

C. Safety and moderation — legitimate interests, Art. 6(1)(f)

  • reviewing reported content and accounts
  • detecting fake profiles, impersonation and stolen photographs
  • removing content that breaks our rules
  • preventing banned members from returning

Our legitimate interest is protecting members from harm. We have weighed this against your privacy and consider it proportionate: the alternative is a platform where abuse goes unchecked.

D. Improving the Service — legitimate interests, Art. 6(1)(f)

  • understanding how features are used
  • improving how foaf converses and how matches are selected
  • diagnosing faults

Where we can do this with aggregated or anonymised data, we do.

E. Marketing — consent, Art. 6(1)(a)

We send promotional email only if you opt in. You can withdraw at any time, and every such email has an unsubscribe link. Service messages — a code to sign in, a notice that someone is waiting to meet you, a receipt — are not marketing and are sent under basis A.

F. Legal compliance — legal obligation, Art. 6(1)(c)

  • keeping accounting and tax records
  • responding to lawful requests from authorities
  • meeting our obligations under the Digital Services Act and other applicable law

5. Artificial intelligence, profiling and automated decisions

foaf is an artificial intelligence. It is not a person. We tell you this before your first conversation begins, in accordance with Article 50 of Regulation (EU) 2024/1689 (the "AI Act"). Every member is told the same thing. No member of foaf is ever presented to you as a human being when it is not one.

What the AI does

foaf reads what you write and builds a structured understanding of you: your personality, your circumstances, your preferences, the way you communicate. It updates this quietly as you talk. It uses that understanding to decide:

  • which members to suggest to you, and in what order
  • which members to suggest you to
  • when two people should be brought together
  • what to say when it introduces you

It also participates in shared conversations — opening them, occasionally contributing, and returning if a member asks it to.

The scores we do not show you

As described in section 3.2, foaf calculates a compatibility estimate, an attractiveness level and a match outcome score. These are internal. They are not published on your profile, not visible to other members, and not visible to you.

We keep the attractiveness level private deliberately. Showing people a number representing how attractive others found them would do harm, and it is not information you need.

Your rights regarding automated processing

Article 22 of the GDPR gives you the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you.

Our view is that suggesting a person you might like to meet does not reach that threshold. Nevertheless, we do not want you to have to take our word for it. If you believe an automated decision has affected you unfairly — for example, if you believe you are being shown to very few people — write to privacy@foaf.app. A human being at HAYDAR SAS will review it, explain what we find, and correct it where correction is warranted.

We do not use your data for automated decisions about employment, credit, insurance, housing, or anything else with legal consequences.

Training

We use your data to operate and improve foaf. We do not sell your conversations, and we do not license them to third parties to train their own models. If we ever wish to use member conversations to train a model in a way that goes beyond operating this Service, we will ask you first.


6. Special category data

Article 9 of the GDPR protects certain categories of data more strictly: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data, health data, and data concerning a person's sex life or sexual orientation.

foaf's conversation may touch on several of these. If you tell foaf that you are looking for a man, or that you observe a religion, or that you do not drink for health reasons, that is special category data.

We process it on the basis of your explicit consent under Article 9(2)(a). You give that consent by choosing to share it. You are not required to answer any question foaf asks — though the less you share, the harder it is for foaf to find someone right for you.

You may withdraw this consent at any time by writing to privacy@foaf.app. We will delete the relevant data. Depending on what you withdraw, we may no longer be able to suggest matches, in which case we will tell you.

We do not use facial recognition, and we do not extract biometric data from the photographs you upload.


7. How we share your information

We do not sell your personal data. We do not share it with advertisers, data brokers, or anyone who wants it for their own purposes.

With other members

When foaf introduces you to someone, it shares a short written description of you, drawn from your profile and your conversations, together with your photograph. What appears in that description is limited to what is appropriate to share with a stranger who may become a friend.

Never shared: your email address, your exact age if you have asked us to keep it approximate, your financial details, your internal scores, anything you have asked foaf to keep private, and any photograph flagged as inappropriate.

If you share a social media link with foaf and it is passed on, we will say plainly that we cannot verify it.

Once a shared conversation opens, whatever you choose to say in it is between you and the other member. Be thoughtful about what you disclose.

With service providers

We use third parties to run the Service. Each acts as a processor under Article 28 of the GDPR — they may only use your data on our instructions, under a written contract:

PurposeWhat they handle
Cloud hosting and databasesAll service data
AI model providersConversation content and profile notes, for generating foaf's responses and assessments
Payment processingCard details, billing information
Email deliveryEmail address, message content
Error monitoring and analyticsTechnical and usage data

We select providers on their security and privacy record, and we review them.

We want to be explicit about one of these: your conversations with foaf are sent to a third-party AI model provider in order to generate foaf's replies. That provider acts as our processor, is contractually barred from using your data for its own purposes, and does not use it to train its models.

With authorities

We may disclose data where we are legally obliged to, or where it is necessary to prevent serious harm to a person. Where the law permits us to tell you, we will.

In a corporate transaction

If HAYDAR SAS is sold, merged or restructured, member data may transfer to the acquiring entity. We will notify you beforehand and your rights under this policy will continue to apply.


8. International transfers

We operate from France. Some of our service providers process data outside the European Economic Area.

Where that happens, we ensure protection through one of the mechanisms in Chapter V of the GDPR:

  • an adequacy decision by the European Commission, or
  • Standard Contractual Clauses approved by the Commission, supported by a transfer impact assessment and, where necessary, additional technical measures.

To ask which providers process data outside the EEA and under which safeguard, write to privacy@foaf.app.


9. Cookies and similar technologies

We use cookies that are strictly necessary to operate the Service — keeping you signed in, remembering your language, protecting against abuse. These do not require your consent.

For anything beyond that, we ask first, through a banner that lets you refuse as easily as accept. Refusing non-essential cookies does not limit your use of the Service.

You can also manage cookies in your browser settings.


10. How long we keep your information

DataRetention
Account and profile dataWhile your account is active
Conversations with foafWhile your account is active
Shared conversations with membersWhile your account is active
PhotographsWhile your account is active, or until you delete them
Derived scoresWhile your account is active
Records of reports and enforcement3 years from the decision
Content removed for illegalityAs required to cooperate with authorities
Payment and transaction records10 years (French Commercial Code, Art. L123-22)
Server logs12 months
Consent records5 years
Anonymised, aggregated statisticsIndefinitely — no longer personal data

Inactive accounts. If you do not sign in for two years, we delete your account and notify you at your registered email address beforehand.

After deletion. When you delete your account we remove your profile and photographs immediately. We keep limited data for thirty days to guard against accidental deletion and to complete any open safety investigation, after which it is erased — except for the records listed above that we are required to keep.

Resetting your conversation. You can reset your foaf conversation from the menu at any time. This deletes your conversations, your suggestions, your matches and the profile foaf has built, and starts you over from the beginning. It does not delete your account.


11. Your rights

Under the GDPR you have the following rights. All of them are free to exercise.

Access (Art. 15). Ask for a copy of the data we hold about you, including the profile foaf has built from your conversations.

Rectification (Art. 16). Correct anything inaccurate. You can also simply tell foaf — it will update its notes.

Erasure (Art. 17). Ask us to delete your data. You can do this yourself from the menu.

Restriction (Art. 18). Ask us to stop processing while a dispute is resolved.

Portability (Art. 20). Receive your data in a structured, machine-readable format.

Objection (Art. 21). Object to processing based on legitimate interests. For direct marketing, your objection is absolute and immediate.

Human review (Art. 22). As described in section 5.

Withdraw consent (Art. 7(3)). Where we rely on consent, withdraw it at any time. This does not affect processing that already took place.

How to exercise them

Write to privacy@foaf.app. We respond within one month. If a request is complex we may extend by two further months and will tell you why within the first month.

We may ask you to confirm your identity. We may decline a request that is manifestly unfounded or excessive, or that would reveal another member's personal data — for instance, a request for a copy of messages another member sent you.

Complaints

If you are unhappy with how we have handled your data, tell us first — we would rather fix it. You also have the right to complain to a supervisory authority. In France:

CNIL — Commission Nationale de l'Informatique et des Libertés 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 www.cnil.fr

If you live in another EEA country you may complain to your own national authority.


12. Security

We protect your data with encryption in transit and at rest, access controls limiting staff access to what their role requires, sign-in by one-time code rather than reusable passwords, logging and monitoring, and regular review of our providers.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the CNIL within seventy-two hours and, where the risk is high, notify you without undue delay.


13. Age requirement

foaf is for adults. You must be 18 or older to use it.

We do not knowingly collect data from anyone under 18. If we learn that a member is under 18 we delete the account and the data immediately.

If you believe a minor is using the Service, report it through the app or write to hello@foaf.app.


14. Changes to this policy

We may update this policy. If a change materially affects your rights or how we use your data, we will notify you by email or in the app at least fourteen days before it takes effect. Continuing to use the Service after that date means you accept the updated policy. If you do not, you may delete your account.

Minor changes — a corrected address, a clearer sentence — take effect on publication.

The effective date is at the top of this page.


15. How to contact us

Privacy: privacy@foaf.app Support: hello@foaf.app

By post: HAYDAR SAS — foaf 47 rue Vivienne 75002 Paris France

Supervisory authority: CNIL, www.cnil.fr


HAYDAR SAS · SIREN 104 899 992 R.C.S. Paris · 47 rue Vivienne, 75002 Paris, France