Privacy Policy
Last updated: 24 September 2026
This policy explains what personal data the OneMessage app ("OneMessage", "we", "us") collects, why, who we share it with, and the choices and rights you have.
1. Who is responsible for your data
The controller of your personal data is Andreas Chouliaras, 28is Oktovriou 43, 45333 Ioannina, Greece.
For any privacy question or request, email privacy@getonemessage.com.
2. What we collect
| Data | Details |
|---|---|
| Account | Your email address, used to sign you in with one-time codes. We don't use passwords. |
| Profile | First name, date of birth (to confirm you are 18+ and show your age), gender, the genders you want to see, bio and photos. Other users see your name, age, bio and photos. |
| Preferences | The age range and maximum distance you choose on Discover. |
| Approximate location | With your permission, your phone's location, which we round to about 1 km before storing. Other users never see your location, only a rounded distance such as "3 km away". |
| Messages | Your one message to each person, whether it was accepted, declined or expired, and your chat messages after acceptance. |
| Safety | People you block, and reports you make about other users, including the reason you give. |
| Device | If you allow notifications, a push notification token and whether your phone runs iOS or Android. |
Sensitive information. The genders you choose to see may reveal your sexual orientation, which the law treats as a special category of data. We only process it with your explicit consent, which you give when you set up your profile, and only to show you relevant people. You can change it at any time in the app, or withdraw consent by deleting your account.
3. Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Creating your account, showing your profile, matching you with people nearby, and delivering messages and chats | Performance of our contract with you (the Terms of Use) |
| Using your approximate location | Your consent, given through your phone's location permission. You can withdraw it in your phone settings. |
| Using the genders you want to see | Your explicit consent (see above) |
| Sending push notifications | Your consent, given through your phone's notification permission |
| Keeping the service safe: enforcing the one-message rule, daily limits, blocking, reviewing reports, and preventing abuse, fraud and underage use | Our legitimate interest in running a safe service, and our legal obligations |
| Sending sign-in codes and essential service emails | Performance of our contract with you |
We do not sell your personal data, show you third-party advertising, or use your data to train AI models.
4. Who we share it with
Other users see your profile (name, age, bio, photos) and a rounded distance. People you message see your message. People you chat with see your chat messages.
Service providers process data on our behalf, under contracts that require them to protect it:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, sign-in, photo storage | United Kingdom (London) |
| Resend | Sending sign-in code emails | European Union (Ireland), with the provider based in the United States |
| Expo (650 Industries) | Relaying push notifications to your phone | United States |
| Google (Firebase Cloud Messaging) | Delivering notifications to Android phones | United States |
| Apple (Push Notification service) | Delivering notifications to iPhones | United States |
Notifications only contain a person's first name and a short line such as "New message". They never include message text.
Where data is transferred outside the European Economic Area, we rely on an adequacy decision (for example for the United Kingdom, or for US companies certified under the EU-US Data Privacy Framework) or on the European Commission's Standard Contractual Clauses.
We may also disclose data if required by law, or to protect someone's safety, for example in response to a valid request from the police.
5. How long we keep it
- We keep your data for as long as you have an account.
- A message request that hasn't been answered expires after 14 days.
- When you delete your account, we immediately delete your profile, photos, location, messages, chats, blocks and the reports you made. Copies in encrypted backups are overwritten within 30 days.
- If we must keep specific data to meet a legal obligation, or to deal with a serious safety report, we keep only what is needed, only as long as needed.
6. Your rights
Depending on where you live, including under the EU and UK GDPR, you have the right to access your data, correct it, delete it, receive a copy in a portable format, object to or restrict certain processing, and withdraw consent at any time (this doesn't affect processing that happened before). You can edit your profile and delete your account directly in the app. For anything else, email privacy@getonemessage.com. We reply within one month.
You also have the right to complain to a data protection authority, for example the Hellenic Data Protection Authority (dpa.gr) in Greece, or the authority where you live.
7. Age requirement
OneMessage is only for adults aged 18 and over. We ask for your date of birth at sign-up and don't allow younger users. If we learn that a user is under 18, we delete their account. You can report a suspected underage user in the app or at hello@getonemessage.com. See our Child Safety Standards.
8. Security
Data is encrypted in transit. Access is restricted by database security rules, so users can only read what they are allowed to see. Your precise location is never stored. No system is perfectly secure, though, so please don't share anything in chats that you wouldn't want someone else to see.
9. Changes
If we make important changes to this policy, we'll tell you in the app or by email before they take effect.