Legal

Privacy Policy

Last updated 10 July 2026

1. Who we are

Ten to One ("we", "us") is a voice-first dating service operated from the United Kingdom. We are the data controller for the personal data described in this policy. For anything privacy-related — questions, requests, complaints — contact privacy@tentoone.app.

This policy covers the Ten to One apps, the tentoone.app website (including the launch waitlist) and related services. It should be read together with our Terms of Service.

2. The data we collect

Data you give us.

  • Account & profile: name, email address, date of birth (to enforce our 18+ rule), gender and the genders you want to meet, bio, interests, relationship preferences, photos and your phone number (used for SMS verification).
  • Voice recordings: your voice intro, the voice notes you exchange with matches and any voice likes you send. This is the heart of the product — if you would rather not have your voice recorded and processed, please do not use Ten to One.
  • Messages & dating activity:text messages in the date-planning phase, your likes/passes, matches, meet/don't meet decisions, planned dates and date feedback.
  • Location: the city/area you set and, if you allow it, your device coordinates — used to show you nearby people and apply your distance preference. We do not track your location in the background.
  • Verification selfie: if you choose photo verification, the selfie you submit for review.
  • Safety data: reports you make or that are made about you, blocks, and optional emergency-contact details you add.
  • Waitlist: the email address and country you submit on this website before launch.

Data we generate or collect automatically.

  • Transcripts: we automatically transcribe voice messages and screen the transcripts against prohibited-term lists to detect scams, harassment and abuse.
  • Usage & analytics: product events (for example account created, first match, date confirmed), timestamps, device type and app version, used in aggregate to understand and improve the product.
  • Payment records: your subscription tier and billing status. Card details are collected and stored by Stripe, not by us.
  • Push tokens: device tokens so we can deliver notifications you have enabled.

3. Why we use your data (lawful bases)

  • To provide the service (contract): creating your profile, showing you people, delivering voice notes and messages, arranging dates, processing subscriptions.
  • Safety and moderation (legitimate interests and legal obligation): transcribing and screening voice content, reviewing reports, verifying photos and phone numbers, enforcing bans, preventing under-18 access, and keeping evidence of serious abuse.
  • Special category data: a dating profile can reveal information about your sex life or sexual orientation (for example, the genders you want to meet). We process this because you deliberately make it part of your profile — processing is necessary for the service you signed up for and is based on your explicit consent, which you can withdraw by deleting the relevant information or your account.
  • Product improvement (legitimate interests): aggregate analytics about how features are used.
  • Communications (consent / legitimate interests): service emails and push notifications (you control each notification type in settings), and marketing only with your consent — off by default.
  • Legal compliance: responding to lawful requests from authorities, tax and accounting duties.

4. Who sees your data

Other users see your profile (photos, bio, age, distance, voice intro) and the content you send them. They never see your email, phone number, exact location or date of birth (only your age).

Our processors. We use a small number of service providers who process data on our instructions:

  • Supabase — our database, authentication and file storage. Our project is hosted in the European Union.
  • Stripe — subscription payments. Stripe acts as our payment processor and as an independent controller for its own fraud prevention.
  • A speech-to-text provider — transcribes voice messages for the safety screening described above.
  • Google Firebase — delivery of push notifications.
  • An SMS provider — sends phone-verification codes.

We do not sell your personal data, and we do not share it with advertisers.

We may disclose data where the law requires it, to protect the safety of a user or the public (for example to law enforcement in connection with a serious report), or as part of a merger or acquisition — in which case this policy continues to apply to your data.

5. International transfers

Your data is stored in the EU (Supabase). Where a processor handles data outside the UK/EEA (for example Stripe or Firebase in the United States), the transfer is protected by an adequacy decision or by the UK International Data Transfer Agreement/Addendum and EU Standard Contractual Clauses, together with additional safeguards where appropriate.

6. How long we keep things (retention)

  • Your account data, content and recordings: kept while your account is active.
  • Account deletion: when you request deletion, your profile is hidden immediately and the account frozen. After a 30-day grace period (you can cancel during it) your profile, photos, voice recordings, transcripts, messages, matches and preferences are permanently deleted from our systems.
  • What survives deletion: payment and tax records (kept up to 6 years as required by law), moderation records connected to serious safety incidents or bans (kept so a banned person cannot simply return), and analytics events that are anonymised — stripped of any link to you — at deletion.
  • Waitlist: kept until launch in your country plus a short wind-down period, or until you ask us to remove you.
  • Backups: encrypted backups roll off on a fixed schedule; deleted data leaves backups within at most 30 additional days.

7. Your rights (UK & EU GDPR)

You have the right to:

  • Access — get a copy of the personal data we hold about you;
  • Portability / export — receive your data in a structured, commonly used, machine-readable format;
  • Rectification — correct inaccurate data (most profile data you can edit yourself in the app);
  • Erasure — have your data deleted (the in-app account deletion described above, or by emailing us);
  • Restriction and objection — restrict or object to processing based on legitimate interests;
  • Withdraw consent — at any time, where processing is based on consent (for example marketing);
  • Not be subject to solely automated decisions with legal or similarly significant effects — our automated transcript screening only flags content for human review; bans are decided by people.

To exercise any right, use the in-app tools or email privacy@tentoone.app. We respond within one month. We may need to verify your identity first.

You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO) — ico.org.uk, or by phone on 0303 123 1113 — or to your local EU data-protection authority. We would appreciate the chance to resolve your concern first.

8. Security

All traffic is encrypted in transit (TLS) and data is encrypted at rest. Voice messages, verification selfies and other private files live in access-controlled storage that other users cannot browse; database access is protected by row-level security so users can only ever read what the product intends them to see. Payment card data never touches our servers. No system is perfectly secure — if we ever discover a breach that puts you at risk, we will notify you and the ICO as the law requires.

9. Children

Ten to One is strictly 18+. We do not knowingly process data about anyone under 18, we technically reject under-18 dates of birth at signup, and we delete accounts (and their data) that we discover belong to minors. If you believe a minor is using the Service, email privacy@tentoone.app.

10. Cookies and the website

The public website sets no advertising or cross-site tracking cookies. The admin area uses strictly necessary session cookies for staff sign-in. Joining the waitlist stores only the email and country you submit.

11. Changes to this policy

We will update this policy as the product evolves. Material changes will be announced in the app or by email before they take effect, and the "Last updated" date above always tells you when it last changed.