Welcome to Unscripted. The Service is operated by Unscripted Technology LLC, an Oregon limited liability company (Oregon Secretary of State Registry Number 258003293) with its principal office at 9233 SE Harney Court, Portland, Oregon 97266 ("we," "our," "us," or the "Company"). We are committed to protecting your privacy and being transparent about how we collect, use, and share your information. This Privacy Policy explains our practices regarding your personal data when you use the Unscripted mobile application and services.
1. Information We Collect
1.1 Information You Provide
- Account Information: Email address, password (encrypted), name, date of birth, and gender identity
- Profile Information: Bio, photos, profile prompt answers, relationship intentions, and preferences
- Sensitive Information (optional): Sexual orientation / relationship intentions and religion / religious beliefs. These are optional, self-reported, shown on your profile, and usable as discovery filters. We process them only with your consent and you may clear them at any time
- Lifestyle Attributes (optional): Height, education level, drinking, and smoking. These are optional, self-reported, shown on your profile, and usable as discovery filters. You may skip any of them during onboarding and add, change, or clear them later
- Location Data: Your approximate location to show you potential matches nearby. We collect your location based on your device settings
- Communications: Messages you send through our platform to your matches
- User Preferences: Search radius, age range preferences, gender preferences, and notification settings
- Payment Information: The optional one-time $1.00 account-verification charge is an in-app purchase processed entirely by the Apple App Store or Google Play, depending on your device. We never receive, see, or store any payment card details — the store processes the payment and provides us only a transaction receipt and the verification outcome.
1.2 Information Collected Automatically
- Usage Information: Your interactions with the app (likes, passes, matches, messages sent/received, screens viewed, and your last-active day). This product-interaction data is recorded and analyzed in our own first-party systems (our Heroku Postgres database); we do not use any third-party product-analytics SDK or service for it. These records contain your numeric user ID, the interaction type, and small technical fields (such as platform and app build) — never your message content, free text, or precise location. They are retained per our Data Retention Policy (§9) and then deleted
- Device Information: Device type, operating system version, app version, device identifiers
- IP Address: Collected automatically when your device connects to our servers. Used only for security, fraud, and abuse detection — never for advertising and never shown to other users
- Device-Attestation Token: A one-time token issued by Apple DeviceCheck or Google Play Integrity, used only to confirm requests come from a genuine, non-tampered device for anti-fraud and bot prevention. Not used for advertising and never shown to other users
- Log Data: Access times, pages viewed, and actions taken
- Push Notification Tokens: Device tokens for sending you notifications
2. How We Use Your Information
We use your information to:
- Provide Our Service: Create and manage your account, show you potential matches, facilitate connections and messaging
- Improve Our Service: Analyze usage patterns to improve app functionality and user experience
- Safety and Security: Verify accounts (including confirming you are a real person via an optional one-time $1.00 card-verification charge), prevent fraud and abuse, enforce our Terms of Service
- Communications: Send you notifications about matches, messages, and app updates
- Legal Compliance: Comply with legal obligations and respond to lawful requests
3. How We Share Your Information
3.1 With Other Users
- Your profile information (name, age, photos, bio) is visible to other users in your discovery queue
- Your location is shared as an approximate distance rounded to the nearest mile (e.g., "5 miles away"), not your exact coordinates
- Messages are visible to your matched users only
- Your email, exact location, date of birth, IP address, and device identifiers are never visible to other users
3.2 With Service Providers
Each service provider is bound by confidentiality and a written agreement, and may only use your information to provide services to us:
- Heroku (Salesforce): Application hosting and Postgres database
- Cloudflare R2: Profile-image object storage
- Cloudflare: DNS and CDN
- Apple Push Notification Service (APNs): Push-notification delivery on iOS (receives your device push token and the notification title / message preview)
- Google Firebase Cloud Messaging (FCM): Push-notification delivery on Android (receives your device push token and the notification title / message preview)
- Google AdMob: Non-personalized in-app advertising (NPA=1; subject to Google's privacy policy)
- Sentry: Crash and error reporting, plus application logging and observability (PII-scrubbed at the SDK boundary; may include technical identifiers such as request IDs and truncated IP-derived metadata)
- Apple DeviceCheck and Google Play Integrity: Device attestation for anti-fraud and bot prevention (each receives a device-attestation token from your device; no profile content or messages)
- OpenAI: Content moderation for messages, bios, and prompt answers, and for your profile photos (both text and images are screened for policy violations)
- Resend: Transactional email delivery (receives your email address and the contents of account emails such as verification, password-reset, and security messages)
- Apple App Store / Google Play: Process the optional one-time $1.00 account-verification in-app purchase. The store handles the payment in full; we receive only a transaction receipt and the verification outcome, never your card number (subject to Apple's / Google's privacy policies)
3.3 For Legal Reasons
We may disclose your information if required by law, court order, or to:
- Comply with legal processes or government requests
- Protect our rights, property, or safety
- Investigate potential violations of our Terms of Service
- Prevent fraud or illegal activities
3.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.
4. Data Storage and Security
- Encryption: Passwords are encrypted using industry-standard bcrypt hashing
- Secure Connections: All data transmission uses HTTPS/TLS encryption
- Data Centers: Your data is stored in secure data centers maintained by our hosting providers
- Access Controls: We implement strict access controls to limit who can access your data
- Regular Security Audits: We regularly review our security practices
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.
5. Your Rights and Choices
5.1 Access and Update
- You can access and update your profile information through the app settings
- You can change your preferences, notification settings, and privacy settings at any time
5.2 Data Export
- You can export your data in a machine-readable format (JSON) at any time via Settings → Privacy → Download My Data
- You may also request a copy by contacting us, and we will respond within 30 days
5.3 Account Deletion
- You can delete your account through the app settings
- Deletion begins a 30-day grace period during which you can restore your account; after 30 days, your profile, photos, messages, and personal information are permanently deleted from production
- Some information may be retained for legal or security purposes (e.g., safety reports)
- Backup copies age out within 90 days
5.4 Location Settings
- You can control location access through your device settings
- Disabling location will limit your ability to see nearby matches
5.5 Marketing Communications
- You can opt out of promotional communications through app settings
- You will still receive essential service-related notifications
6. Data Retention
We retain your information for as long as your account is active or as needed to provide our services. Specific retention periods:
- Active Accounts: Data retained while your account is active
- Deleted Accounts: 30-day grace period during which you can restore; after 30 days, data is permanently deleted from production and backups age out within 90 days
- Legal Requirements: Some data may be retained longer to comply with legal obligations
- Safety Data: Reports of abuse or violations may be retained for safety purposes
- Payment-Verification Records: If you complete the $1.00 verification charge, the App Store / Google Play transaction identifier and verification outcome (never your card number) are retained for 7 years for tax and accounting compliance
7. Content Removal Requests
In addition to the general Deletion right described above, Unscripted operates a dedicated content-removal intake for material that you have a specific legal right to have removed.
TAKE IT DOWN Act intake (non-consensual intimate imagery): Under 15 U.S.C. §6851 et seq., individuals depicted in non-consensual intimate imagery (NCII), or their authorized legal representatives, may request the removal of such imagery from our platform. To submit a request:
- Email: takedown@unscripteddating.app
- In-app: Settings → Safety & Reporting → Report Content
- Required information: a description of the imagery, the URL or in-app location where it appears (profile, message, or other surface), your relationship to the depicted individual (self or authorized representative), and a statement, made under penalty of perjury, that the imagery is non-consensual and that you (or the individual you represent) are depicted.
Service-level commitment: we will remove qualifying material within 48 hours of receiving a valid request and will make reasonable efforts to remove identical copies that subsequently re-appear on the platform. Identical and visually-similar copies of the depicted material are detected at intake using a combination of (a) SHA-256 cryptographic hashing for byte-identical matches and (b) perceptual hashing (pHash) for visually-similar matches with hamming distance ≤ 6 of the depicted material. Matching profiles are flagged for the founder's review within the 48-hour SLA. Every valid takedown request also receives a founder manual review as a belt-and-suspenders check beyond the automated sweep.
Recordkeeping: we retain a non-substantive record of each takedown request (submitter contact, timestamps, SHA-256 hex of the depicted material, decision, action taken) for 7 years, consistent with regulatory recordkeeping practice. The removed imagery itself is deleted from production storage and from Cloudflare R2 as part of the founder's manual review pass within the 48-hour SLA, via the same profile-image-delete pipeline that powers user-initiated photo removal; only the operational metadata is retained.
DMCA notices: copyright infringement notices are not handled through the takedown alias. See the Terms of Service §C for the §512(c)(2) Designated Agent (dmca@unscripteddating.app).
Other removal requests: privacy violations, impersonation, and harassment that do not fall under the TAKE IT DOWN Act remain handled through the standard in-app Report flow and abuse@unscripteddating.app.
8. Children's Privacy
Unscripted is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 18. If we discover that we have collected information from a minor, we will delete it immediately. If you believe we have information about someone under 18, please contact us.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using Unscripted, you consent to the transfer of your information to our facilities and service providers wherever located.
10. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You can request information about the personal data we collect, use, and share
- Right to Delete: You can request deletion of your personal information
- Right to Opt-Out: You can opt out of the sale of personal information (Note: We do not sell your personal information)
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights
To exercise these rights, contact us using the information below.
11. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):
- Right of Access: Request copies of your personal data
- Right to Rectification: Correct inaccurate personal data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Request limitation on processing your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing of your personal data
- Right to Withdraw Consent: Withdraw consent at any time
Legal Basis for Processing: We process your data based on:
- Your consent for profile creation and matching
- Your explicit consent for any special-category data you choose to provide (for example, religion / religious beliefs and sexual orientation), which you may withdraw at any time by clearing those optional fields
- Performance of our contract with you (Terms of Service)
- Legitimate interests in providing and improving our service
- Compliance with legal obligations
12. Third-Party Services
11.1 Google AdMob
We use Google AdMob to display advertisements. AdMob may collect device information and usage data. For more information, see Google's Privacy Policy.
11.2 Apple Services
We use Apple Push Notification Service (APNs) to deliver notifications. Apple may collect device tokens and delivery metrics. See Apple's Privacy Policy.
11.3 App Store & Google Play (Payment Processing)
The optional one-time $1.00 account-verification charge is an in-app purchase processed by the Apple App Store (iOS) or Google Play (Android). The store handles the payment in full and we never receive or store your card details — only a transaction receipt and the verification outcome. See Apple's Privacy Policy and Google's Privacy Policy.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you through:
- In-app notification
- Email notification to your registered email address
- Prominent notice on our website
Your continued use of Unscripted after changes take effect constitutes acceptance of the updated Privacy Policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Unscripted Technology LLC
Address: 9233 SE Harney Ct, Portland, OR 97266
In-App: Settings → Help & Support
Role-based aliases (all route to the founder; published so that regulators, AGs, copyright owners, and depicted individuals have a stable address that does not change with operator turnover):
- support@unscripteddating.app — general user support
- privacy@unscripteddating.app — Privacy Policy contact, DSAR (data subject access requests), correction, deletion, CCPA/GDPR inquiries
- legal@unscripteddating.app — legal notices, Attorney General / regulator correspondence, subpoenas, civil process
- dmca@unscripteddating.app — DMCA §512(c)(2) Designated Agent (copyright infringement notifications and counter-notifications)
- takedown@unscripteddating.app — TAKE IT DOWN Act intake for non-consensual intimate imagery (48-hour SLA)
- abuse@unscripteddating.app — safety and abuse reports, including impersonation and harassment that fall outside the TAKE IT DOWN Act
We will respond to your request within 30 days.