This policy applies to the All Clear apps for iPhone and Android, the website at allclear.dating, and any related support channels. All Clear is offered to residents of the United States. By using All Clear you agree to the practices described here.
All Clear is operated by Spoon Seller LLC, a Virginia limited liability company, doing business as All Clear. Our job is to filter your dealbreakers before a date — not to sell or analyze who you are. This is the full policy, in plain English.
This policy applies to the All Clear apps for iPhone and Android, the website at allclear.dating, and any related support channels. All Clear is offered to residents of the United States. By using All Clear you agree to the practices described here.
Account: email, password (stored hashed), date of birth (used only to enforce 18+), first name, and gender (currently "man" / "woman" — a beta-stage constraint; will expand).
Dealbreaker answers: structured responses about relationship intent, kids, distance, lifestyle, faith, politics, family boundaries, finances, conflict approach, and schedule — used to filter incompatible matches.
Sensitive answers: faith and politics are sensitive. We process them only with your explicit consent, which you give at signup, and you can withdraw it any time.
Photos: optional; stored encrypted and served via short-lived signed links.
Location (optional): if you choose, either your phone's approximate location or a ZIP code you type. We turn it into your city and a rough area — never your exact spot — so we can introduce you to people near you. You can skip it; we just can't show you people close to you without it.
Messages: what you exchange with matches after clearance. Stored at rest; never shown to anyone outside the conversation.
Reports: if you report someone, we keep the report — even after either account is deleted — for safety recordkeeping.
Device and usage signals: device type, browser or OS, app version, crash reports, and feature-usage events.
Website analytics (optional): Google Analytics 4 loads only after you choose Accept analytics. It may collect pages viewed, navigation events, referring site, device/browser details, and approximate location derived from your IP address, and it sets analytics cookies or similar identifiers. If you reject analytics, the Google Analytics scripts do not load.
Web storage: one signed, HttpOnly sign-in cookie keeps you logged in. Your versioned analytics choice is stored in localStorage so we can honor it. We do not set advertising cookies or use analytics for cross-context behavioral advertising.
Sign in with Apple (if you choose it): Apple sends us your Apple user ID and the email or relay address you authorize.
Payments: Apple and Google process all payments. We see subscription status and transaction identifiers — never your card number.
What we collect: before your matches are shown, the app asks for a short live selfie. It checks two things — that you're a real, live person, and that you're the person in your main profile photo. The camera is only used with your permission, and only during this check.
How it works: the selfie video goes straight from your phone to Amazon Web Services (Amazon Rekognition Face Liveness), which runs the check for us in the United States. Amazon sends our server one still frame from the selfie, and we compare it with your main profile photo using the same Amazon service (Amazon Rekognition CompareFaces).
What we keep: only the result — pass or fail, two scores (how sure the live check is, and how closely the faces match), the date, and which of your profile photos was checked. We never save your selfie video, the still frame, or any face template, faceprint, or other face measurements. The still frame is held in memory only for the few seconds the comparison takes, then thrown away.
Who sees it: face data goes only to Amazon Web Services, acting as our service provider, and only to run this check. Amazon may keep it only as long as it needs to run the check, and we have opted out of Amazon using it to improve its own products. We never sell it, never show it to other members, and never use it for advertising, for matching, or to train AI.
How long: the selfie and still frame are not kept by us after the check finishes. The pass/fail result is kept until you delete your account (it is deleted with your account) or until you change your main photo, which starts a new check.
Your choice: the check is optional, but your matches stay hidden until it is done. You can delete your account, and with it the result, any time in your Profile → Delete my account.
To run the four jobs of the product — collect evidence, clarify what's missing, filter hard stops, reveal cleared intros — plus: verify you're 18+, provide subscription benefits, send transactional messages (opt out of non-essential ones in settings), investigate safety reports, meet legal obligations, and improve the product with aggregate, de-identified analysis. We do not use your data to train third-party AI models. We do not sell personal information, and we don't share it for cross-context behavioral advertising.
The other side of an introduction — only after both sides clear dealbreakers.
Service providers bound by contract: Supabase (database + storage), Vercel (web hosting), Railway (API hosting), Sentry (error monitoring), Google Analytics (optional website usage analytics after consent), Google Firebase Crashlytics (crash reports from the Android app — the error, device model, OS and app version, and a random install ID; never your name, email, photos, messages, or answers; kept up to 90 days), Amazon Web Services (the photo check — see section 04), Apple and Google (purchases), Apple and Firebase push services (notifications).
Law enforcement, in response to a legally valid request, after reasonable review of scope and jurisdiction.
A buyer, if the company is ever acquired — your data stays subject to this policy unless you agree otherwise. And you, in your data export. We never sell personal information.
All Clear is operated from the United States and your data is stored in the United States. The service is US-only at launch. If we expand to the EEA, UK, or elsewhere, we will appoint any required local representatives and adopt approved data-transfer mechanisms before serving those regions, and update this policy. The substantive commitments here — explicit consent for sensitive answers, deletion rights, no selling — apply to everyone who uses All Clear.
Active account data: kept until you delete your account.
Deleted accounts: a minimal audit record for 12 months, for safety and abuse prevention.
Safety reports: 24 months, then de-identified.
Payment records: 7 years (tax compliance).
Server logs: 30 days.
Photo check: the selfie and still frame are not kept after the check; the pass/fail result is kept until you delete your account.
Website analytics events: up to 14 months in Google Analytics; your local consent choice remains until you change it or clear site data.
Access a copy of your personal data.
Correct inaccurate data.
Delete your account and data, in-app: your Profile → Delete my account.
Receive a portable copy of your data.
Object to processing, and withdraw consent at any time.
Opt out of non-essential communications.
California privacy law (CCPA/CPRA) also gives you the right to know, delete, correct, limit use of sensitive personal information, and opt out of sale or sharing — we do neither. We will never treat you differently for exercising any privacy right. Send requests to support@allclear.dating; we respond within 45 days, extendable where the law allows, and may verify you control the account email first.
All Clear is for adults 18 and over. We do not knowingly collect information from anyone under 18. If we learn of an underage account, we terminate it and delete the data. Parents or guardians can write to support@allclear.dating.
Safeguards include encrypted transport (TLS 1.2+), encryption at rest for the database and photo storage, access controls with multi-factor authentication for production systems, audit logging on privileged actions, and annual review of access grants. No system is perfectly secure; if a breach affects your personal data, we will notify you and regulators as applicable law requires.
The matching engine uses deterministic, rule-based logic to filter dealbreakers. It does not make legally significant decisions about you. You can request human review of any match decision at support@allclear.dating.
We'll post material updates here and notify you in-app and by email at least 14 days before they take effect.
All Clear sends SMS text messages only for limited, transactional purposes — for example, when a member sends a ClearPass invite we deliver a one-time text on their behalf to the phone number they enter, inviting the recipient to answer dealbreaker questions, and we may send one-time account or verification codes you request. Message frequency is limited and transactional; this is not a marketing or recurring-subscription messaging program. Message and data rates may apply. Reply STOP to any message to opt out of further texts, or HELP for help. We do NOT sell or rent mobile phone numbers, and we do NOT share mobile information, SMS opt-in, or consent data with any third parties or affiliates for their own marketing or promotional purposes. A phone number you provide is used solely to deliver the message you requested and is handled under this policy.
Privacy questions, data requests, and legal notices: support@allclear.dating. We are an online-only service operated by Spoon Seller LLC; email is the designated contact method for all legal and privacy matters.