Privacy Policy
Your privacy matters — how we collect, use, safeguard, and govern your personal information.
Last updated: March 19, 2026
Hven (“we,” “us,” or “our”) is committed to protecting your privacy and handling your personal information responsibly and lawfully. This Privacy Policy explains what information we collect, how we use it, how it is shared, your rights and choices, and the measures we take to safeguard your data. Your use of the Services is also governed by our Terms of Service and Community Guidelines. By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy.
Definitions
Personal Data / Personal Information: Any information relating to an identified or identifiable individual.
Sensitive Personal Data: Personal Data subject to heightened protections under applicable laws, including precise location data, government-issued identification, biometric data, sexual orientation, or information relating to intimate life.
Processing: Any operation performed on Personal Data, whether automated or manual.
User: Any individual who accesses or uses our Services.
Services: The Hven mobile application, website, matchmaking features, events, communications tools, and related offerings.
Information We Collect
Account and Profile Information: Name, email address, phone number, date of birth, age, gender, preferences, biography, profile photos, and other information you choose to provide.
Sensitive and Optional Profile Information: Information that may reveal sexual orientation, dating preferences, or lifestyle choices, where voluntarily provided.
Communications Data: Messages, media, and other content exchanged through the Services. We do not routinely monitor private communications; however, content may be processed using automated systems, including artificial intelligence systems provided through third-party infrastructure such as OpenRouter, or human review where necessary to operate the Services, investigate reports, prevent fraud or abuse, comply with law, or enforce our Terms and Community Guidelines. AI processing of communications occurs only when required for specific features such as safety analysis or AI-assisted functionality.
Usage and Interaction Data: Matches, interactions, event participation, feature usage, moderation actions, logs, and analytics.
Device and Technical Data: Device model, operating system, app version, IP address, device identifiers, language settings, crash reports, and diagnostics.
Location Data: Approximate or precise location data, collected only with your explicit permission and used for matchmaking, event relevance, and safety features.
Media Data: Photos, videos, and audio recordings you upload or create within the Services.
Verification Data: Government-issued identification, selfies, or facial comparison data used solely for age, identity, or safety verification.
Payment and Transaction Data: Subscription status, purchase history, and transaction confirmations processed by third-party payment providers.
Safety and Moderation Data: Reports, complaints, behavioral indicators, enforcement decisions, and records necessary to maintain platform safety and integrity.
Sensitive Personal Data and Special Category Information
Some Personal Data processed by Hven may be classified as sensitive or special category data under applicable privacy laws.
This includes precise location data, government-issued identification, biometric or facial comparison data (where applicable), information relating to sexual orientation or intimate life, communications reviewed for trust and safety purposes, and moderation or enforcement records.
Where required by law, such data is processed based on explicit user consent, necessity to protect vital interests or user safety, performance of our Services, legitimate interests such as fraud prevention, or compliance with legal obligations.
You may withdraw consent for certain sensitive data processing at any time; however, this may limit or disable specific features of the Services.
How We Use Your Information
To provide, operate, and maintain the Services.
To create, manage, and personalize accounts, matches, recommendations, and experiences.
To facilitate communications and interactions between users.
To verify identity, confirm eligibility, and prevent underage access.
To promote safety, detect and prevent fraud, abuse, harassment, or other harmful conduct.
To enforce our Terms of Service, Community Guidelines, and related policies.
To analyze usage, conduct research, improve performance, and develop new features.
To send service-related notifications, support responses, and marketing communications where legally permitted.
To comply with legal obligations, regulatory requirements, and lawful requests from authorities.
To generate match suggestions, compatibility insights, and safety signals using AI systems based on your profile data, preferences, and interactions.
Matchmaking, Profiling, and Automated Processing
Hven uses automated systems and algorithms to suggest matches, events, and recommendations based on profile information, stated preferences, activity patterns, proximity, and engagement signals.
These processes may include artificial intelligence systems that analyze user data to improve compatibility and safety outcomes.
These processes are designed to enhance relevance, compatibility, and safety and do not produce legal or similarly significant effects without human involvement where required by law.
Depending on your jurisdiction, you may have the right to object to or request limitations on certain profiling or automated processing activities.
Artificial Intelligence and Third-Party AI Processing
Hven uses artificial intelligence technologies to support matchmaking, safety analysis, content moderation, and certain in-app features.
AI processing occurs only when necessary to provide specific functionality, such as generating match suggestions, analyzing compatibility signals, detecting harmful behavior, or assisting with user interactions.
When these features are used, limited portions of user data may be transmitted to third-party AI infrastructure providers, including OpenRouter, which routes requests to large language models operated by third-party providers.
Data transmitted may include profile attributes such as age, preferences, and interests, and, where relevant, portions of messages or user-generated content required to perform the requested feature.
Data is transmitted only at the time of the AI request and is not continuously shared.
Hven configures AI processing to use zero-data-retention (ZDR) compliant models where available, meaning that AI providers are contractually restricted from storing, retaining, or using submitted data to train their models.
AI providers act solely as data processors on our behalf and are contractually prohibited from using your data for their own purposes, including model training, advertising, or independent profiling.
AI processing is used only to operate and improve core features of the Services and is not used for advertising or for training third-party models using your personal data.
Legal Basis for Processing
UAE (PDPL): Consent, contractual necessity, legitimate interests, or legal obligation.
EU / UK (GDPR & UK GDPR): Consent, performance of a contract, legitimate interests, compliance with legal obligations, and protection of vital interests.
United States (CPRA/CCPA, VCDPA, CPA, and similar laws): Notice, consent where required, and rights to limit or opt out of certain data uses.
Canada (PIPEDA): Express or implied consent, legitimate business purposes, and legal compliance.
Other Jurisdictions: Processing is conducted in accordance with applicable local laws and generally accepted privacy principles.
Data Retention
Personal Data is retained only for as long as necessary to fulfill the purposes described in this policy.
Account and profile data is retained while your account remains active and deleted or anonymized within a reasonable period following account deletion, subject to legal, safety, or fraud-prevention requirements.
Verification data is retained only as long as necessary to complete verification and comply with regulatory obligations.
Safety, moderation, and enforcement records may be retained for extended periods to prevent repeat violations and protect users.
System logs and backups are retained on a limited rolling basis and securely deleted according to internal retention schedules.
Your Rights and Choices
Depending on your location, you may have the right to access, correct, update, delete, restrict processing, object to processing, withdraw consent, or request data portability.
You may opt out of marketing communications at any time through in-app settings or unsubscribe mechanisms.
You may designate an authorized agent to submit requests on your behalf where permitted by law.
Certain rights may be limited where fulfilling a request would infringe on the rights of others, compromise safety, interfere with investigations, or violate legal obligations.
You may lodge a complaint with your local data protection authority.
To exercise your rights, contact us at [email protected].
California and US State Privacy Disclosures
Hven does not sell Personal Data.
Hven does not share Personal Data for cross-context behavioral advertising without consent where required by law.
Residents of certain US states may have the right to limit the use of sensitive personal information, opt out of certain processing, and request information regarding data disclosures in the preceding 12 months.
Hven does not discriminate against users for exercising privacy rights.
Where applicable, Hven honors recognized opt-out preference signals such as Global Privacy Control (GPC).
International Data Transfers
Your information may be transferred to and processed in jurisdictions including the United Arab Emirates, European Union, United Kingdom, United States, and Canada.
Where required, we rely on adequacy decisions, Standard Contractual Clauses, UK International Data Transfer Agreements, or equivalent safeguards.
Additional technical and organizational measures, including encryption and access controls, are applied to protect transferred data.
Where AI processing involves infrastructure in other jurisdictions, the same safeguards and protections apply.
Data Security
Encryption of sensitive data in transit and at rest.
Role-based access controls and authentication mechanisms.
Regular security monitoring, audits, and infrastructure hardening.
Incident detection, response, and breach notification procedures.
While no system can guarantee absolute security, we employ reasonable and industry-standard safeguards.
Data Sharing and Third-Party Services
We may share Personal Data with trusted service providers supporting hosting, analytics, communications, customer support, trust and safety, identity verification, payment processing, marketing, and artificial intelligence processing.
AI processing requests are transmitted through OpenRouter to third-party model providers selected for their compliance with strict privacy and zero-data-retention requirements.
These providers are contractually required to protect Personal Data and are prohibited from using it for their own purposes, including training or advertising.
We may disclose information to regulators, courts, or law enforcement where legally required or permitted.
Children’s Privacy
The Services are intended solely for individuals aged 18 and older.
We do not knowingly collect Personal Data from minors.
If underage use is identified, we will delete associated data and terminate the account.
Providing false age information violates our Terms of Service.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect legal, regulatory, or operational changes.
Material updates will be communicated through the Services or by email.
Continued use of the Services after updates constitutes acknowledgment of the revised policy.
Contact Us
For privacy inquiries, rights requests, or complaints, contact [email protected].
Business Address: Hven Co. FZE LLC, Amber Gem Tower, Sheikh Khalifa St., United Arab Emirates.
This Privacy Policy is intended to comply with applicable data protection laws, including UAE PDPL, EU and UK GDPR, Canada PIPEDA, and U.S. state privacy laws such as CPRA/CCPA and VCDPA. Additional rights or disclosures may apply depending on user location.