Effective 3 September 2026
Privacy policy
A dating profile is some of the most personal data you will ever hand to a company. Here is exactly what we collect, what we do with it, and what we refuse to do with it — in plain language, not legalese.
Who we are
Just Curves is a dating service for plus-size women and the people who want to date them. This policy explains what we do with your personal information when you use justcurves.app or our mobile apps.
If you have a question about anything here, or you want to exercise one of the rights described below, email privacy@justcurves.app.
What we collect
Account data: your email address and a one-way cryptographic hash of your password. We never store your password itself and cannot recover it.
Profile data you choose to provide: display name, date of birth, gender and pronouns, orientation, city and region, an approximate latitude and longitude derived from that city, headline, bio, occupation, education, relationship goals, lifestyle answers, languages, interests, and prompt answers.
Photos you upload. These are stored privately on our own servers, not on a third-party image host.
Activity data needed to make the product work: who you liked or passed on, your matches, your messages, blocks, reports you file, profile views, notifications, and your last-active timestamp.
Subscription and billing data if you choose a paid plan: your subscription tier, its start and renewal dates, usage counters (likes and Super Likes used, rewinds used), and the customer identifier and subscription identifier Stripe assigns to you. Card numbers, expiry dates, and full payment details are never stored on our servers — payments are processed by Stripe, a PCI-DSS Level 1 payment provider, and we only retain the identifiers needed to recognise your subscription and link it to your account. Stripe's own handling of your card data is governed by Stripe's privacy policy.
A short-lived archive of your most recent swipe per profile, kept so you can undo your last swipe within seven days. It contains only which member you swiped and what kind of swipe it was.
Advertising delivery data for free accounts: a swipe counter, the time an in-feed ad was shown, its placement, and the advertising network label. We use this to enforce pacing and daily limits; it does not include message content or precise location.
Technical data: the IP address and user-agent string attached to a sign-in session, used for security and abuse prevention.
Sensitive information
Some of what you put on a dating profile is legally sensitive — information that may reveal your sexual orientation, your health, or your religion. We only process it because you chose to publish it on your profile, and we use it solely to operate the matching service.
You are never required to fill in these fields. Everything except your email, password, date of birth, and gender is optional, and you can remove any of it at any time from your profile settings.
How your data is used
To authenticate you and keep your account secure.
To build your Discover feed. Matching uses your stated preferences and profile attributes — shared interests, relationship goals, approximate distance, recent activity, verification status, and profile completeness. Compatibility filtering is bidirectional: we respect both your preferences and the other member's.
To deliver likes, matches, messages, and notifications.
To honour your subscription: apply your plan's like and Super Like allowances, let you browse who liked you and who viewed your profile, and keep your Undo history. Paid members never see in-feed advertising.
To bill subscriptions through Stripe, handle renewals, failed payments and refunds, and remind you when a payment needs attention.
To pace clearly labelled in-feed advertising for free members and prevent repetitive or excessive ad delivery.
To enforce our community guidelines, review reports, and remove members who make the platform unsafe.
To diagnose faults and protect the service against abuse, spam, and credential-stuffing attacks.
Payments
Paid subscriptions are billed through Stripe. When you upgrade, you enter your payment details on a Stripe-hosted checkout page; that data goes to Stripe, not to us. We never see or store your full card number.
We keep the Stripe customer and subscription identifiers alongside your account, plus the billing status of your plan (active, cancelled, in a payment-failure grace period, or ended). This is what lets us grant and remove access correctly, honour cancellations, and answer billing questions you raise with support.
Where a subscription is purchased through the Apple App Store or Google Play instead, the store processes the payment and receives your billing details; we receive only the entitlement.
If a payment is refunded or disputed, we end the paid access the payment covered. We keep minimal transaction records (dates, amounts, identifiers) for accounting and tax purposes, in line with our retention rules below.
What we never do
We do not sell your personal information.
We do not share your profile, messages, or photos with advertisers or data brokers.
We do not run third-party advertising trackers or advertising cookies on Just Curves.
We do not read your private conversations for advertising or profiling. Direct messages are end-to-end encrypted between matched members.
We do not publish your exact location. Distance is computed from the approximate coordinates of the city you entered, and other members only ever see a distance, never a precise position.
Who can see what
Your profile and approved photos are visible to other signed-in members who match your discovery criteria. Just Curves is not a public website — profiles are not indexed by search engines and are not viewable without an account.
Photos you upload are reviewed before they appear anywhere. Until a moderator approves a photo, only you can see it.
Photos added to an active Hush are visible only to you and the other consenting participant after moderation approval. They never appear in Discover or on either public profile. Closing a Hush immediately removes the other participant's access.
Blocking is mutual and silent: a blocked member disappears from your feed, cannot contact you, cannot view your profile, and is not told that you blocked them.
Our trust and safety team can see the content of a report you file and the profile of the member you reported. They cannot read your end-to-end encrypted messages.
Cookies and similar technologies
We use strictly necessary cookies only: a session cookie that keeps you signed in, and a cross-site request forgery token that protects your account from malicious websites. There are no analytics or advertising cookies.
Your theme preference is stored locally in your own browser and never sent to us.
How long we keep things
Your account data and profile are kept while your account exists. When you delete your account, your profile, photos, preferences, likes, matches, messages, swipe-undo archive, encryption keys, subscription record, notifications, and support history are removed. The remaining identity is pseudonymized and cannot be used to sign in.
When you delete an account that has an active Stripe subscription, we cancel the subscription so Stripe stops charging you. Stripe retains its own transaction records under its retention policy, as payment processors are required to do.
Messages are soft-deleted when a match ends, so that a member who is later reported cannot destroy the evidence of harassment. They are not visible to either party once the match is over.
The swipe-undo archive is deleted after seven days, or immediately once you undo the swipe.
Profile views are retained for 90 days and then pruned automatically.
Safety reports and moderation decisions are retained as an audit trail after resolution, because a pattern of reports across time is exactly what makes enforcement possible.
Encrypted database backups are retained for up to 30 days and then destroyed.
Security
Passwords are hashed with bcrypt. Direct messages are end-to-end encrypted, so the contents are not readable on our servers.
The database is not reachable from the internet, all traffic is served over HTTPS, the application runs as a sandboxed least-privilege system account, and backups are encrypted at rest.
Signing out revokes your session server-side, and suspending an account invalidates every one of its active sessions immediately.
No system is perfect. If you believe your account has been compromised, change your password and contact us.
Your rights
You can access and correct almost everything directly in the app: edit your profile, replace or delete photos, change your preferences, manage your block list, and see your plan and billing status in Settings → Subscription.
You can cancel a paid subscription at any time from Settings → Subscription → Manage billing, which Stripe handles directly — the change takes effect without us touching your data.
You can delete your account at any time from Settings → Delete account. The public account-deletion page also explains the process and provides a contact route if you cannot sign in.
Depending on where you live you may also have the right to a copy of your data, to restrict or object to processing, or to lodge a complaint with a data protection authority. Email privacy@justcurves.app and we will respond within 30 days.
Age restriction
Just Curves is strictly for adults aged 18 and over. Members must provide a date of birth and attest that it is accurate; registration rejects a self-reported age under 18. We do not currently perform documentary age verification. We do not knowingly collect information from children. If you believe a minor is using the service, report the profile immediately — 'underage' is a dedicated report category and we treat it as urgent.
Changes to this policy
If we make a material change to how we handle your information, we will tell you in the app before it takes effect. The effective date at the top of this page always reflects the current version.
Questions about your data?
Email privacy@justcurves.app and a real person will answer. You can also read our terms, our pricing promise, and the community guidelines that govern how members treat each other.
