RM RF LABS F.Z.E

Privacy Policy

Effective 30 August 2026

Last updated 30 August 2026.

Who we are

DateShip is operated by RM RF Labs F.Z.E, Office C1, 1F, SF7931, Ajman Free Zone, Ajman, United Arab Emirates. For privacy questions and requests, email support@dateship.app.

Information used by the app

Account information includes your email, display name, optional gender, linked sign-in identities and sessions. Email passwords are stored as Argon2id hashes, not as plain text. Pair data includes the relationship between two accounts, date progress, shared photos and memory captions. Gender is optional and is not shown to your partner.

How information is used and shared

Information is used to authenticate you, manage your pair, provide dates and maintain your shared album. Shared content is visible to the two members of your pair within the app, not through public profiles. This does not mean end-to-end encryption or that the service operator has no technical access. DateShip supports sign-in by email and password, Google and Apple. Google and Apple verify the corresponding sign-in identities. Account and pair data are kept while the account remains active and are not deleted solely because the app has not been used.

Device permissions, notifications and local storage

The camera is used for date photos and pairing QR codes. Photo access lets you select or save images. The app does not use location, advertising identifiers, advertising or cross-app tracking. Session tokens are stored in device secure storage; language and interface preferences are stored locally. If notifications are enabled, DateShip uses Apple Push Notification service on iOS and Firebase Cloud Messaging on Android to tell a partner that the other person completed an action or is waiting for them. Device push tokens are used only to deliver these service notifications and must be removed when the account is deleted. Product analytics is described separately below.

Infrastructure, email and backups

The production server is hosted by Hetzner Online GmbH in Falkenstein, Germany. The implementation uses PostgreSQL and stores uploaded files on the application server. Hetzner creates daily full-disk backups and retains up to seven rotating backup slots; the oldest backup is replaced when a new one is created. Data deleted from the active system may therefore remain in a backup until that backup is rotated out. DateShip uses Resend to deliver transactional account messages such as email verification and password reset. These messages are not used for marketing. No AI service processes app content in the implementation described.

Server logs and IP addresses

Application logs remain on the server and are deleted through size-limited log rotation, typically leaving one to two weeks of history. They do not contain email addresses, names, authentication tokens or message bodies. The reverse proxy records IP addresses in access logs solely to protect the service against abuse. Those access logs are retained for no longer than 14 days. Logs are not sent to external logging, monitoring or error-tracking services.

Product analytics

DateShip uses Amplitude, Inc. in its EU data region to understand use of product features and improve the app. The implementation sends a limited set of manually defined events with a pseudonymous analytics identifier. It does not send names, email addresses, gender, partner or pair identifiers, photos, captions, memory content, QR codes, invitations, push tokens or advertising identifiers. Session Replay, Autocapture and advertising attribution are not enabled. Analytics data will follow the standard retention available under the active Amplitude plan; the current Free plan permits queries covering up to one year. This query window should not be read as a promise that Amplitude physically deletes every older copy on that exact date. When an account is deleted, DateShip stops future analytics collection for it and submits its analytics identifier through Amplitude’s privacy deletion process.

Account deletion and leaving a pair

An account can be deleted in Profile by selecting Delete Account and completing the irreversible confirmation shown by the app. Deleting the account removes account records, sign-in identities, sessions and associated pair data from the active system. Leaving a pair or deleting either account deletes the shared album, photos, memories, active date and pair progress for both partners. This cannot be undone within the app. Deleted information may remain temporarily in one of up to seven daily rotating server backups and is removed as those backups are replaced. Backups are used for disaster recovery and are not accessed as part of normal app operation.

Your choices and contact

You may omit gender, manage linked sign-in methods while keeping at least one, and revoke camera or photo permissions in your device settings. Contact support@dateship.app about access, correction, deletion or concerns about shared content. An automated data export is not currently available. DateShip is intended for people aged 16 and over.

support@dateship.app