Pipe policies
Privacy Policy
Effective September 1, 2026. This policy explains what Pipe collects, why we use it, when we share it and the choices available to you. Pipe is an adults-only dating service available internationally.
Effective and last updated: September 1, 2026
1. Who this covers
This policy applies to the Pipe mobile application, pipedating.com and the services that link to it. “Pipe,” “we,” “us” and “our” refer to the operator of those services. By using Pipe, you acknowledge the practices described here.
2. Information we collect
Account and authentication. We process information such as your email address, password hash, account identifiers, sign-in provider identifier, session and device-installation identifiers, date of birth and age-eligibility result.
Profile and compatibility. This can include your name, adult profile photos, conversation starters, relationship intentions, gender and orientation, preferences, parenting context, whether you are open to dating a parent, broad availability and other answers you choose to provide.
Location. With permission, Pipe receives your device coordinates during a foreground location request and keeps them in a restricted location record to derive a protected dating area, calculate distance and show relevant people. If you choose nearby venue search, foreground location may also be used to find public meeting places. Other members receive only an approximate area or distance, never your coordinates or live movement. Pipe does not request or collect background location.
Activity and communications. We process likes, passes, matches, messages, blocks, reports, notification choices, account settings, support requests and safety interactions.
Date planning and Safe Date. If you use date-planning features, we process the date, time, venue proposal and response needed to coordinate with your match. A Safe Date plan is separate and private to you. It may include the scheduled time, venue, your match's first name, check-in time and sharing state. Your match does not receive your private Safe Date plan. Selected plan details leave Pipe only when you deliberately use your device's share options.
Verification and moderation. We process photo-review results, automated policy signals, photo-confirmation status and evidence needed to investigate reports or appeals. If you choose photo confirmation, Pipe creates a hosted inquiry with Persona Identities, Inc. Persona collects a short selfie or video and related device or browser signals directly in its hosted flow so the recent capture can be compared with your current adult profile photos. This check is not a government-ID, legal-name, background or exact-age verification. Persona presents its own capture, consent and retention notice before collection.
Pipe stores the Persona inquiry reference, result, timestamps and the profile-photo set to which the result applies. The Pipe app does not publish or place the hosted selfie or video in your profile or messages. Access to provider-held inquiry information is limited to authorized support, fraud, safety, privacy and legal work where necessary.
Technical and operational data. We receive IP address, request and security logs, app version, operating system, device and push-token information, crash or performance data, and fraud or abuse signals.
Product journey data. Pipe records a limited set of first-party events such as an app opening, an onboarding step being viewed or saved, a main tab being opened, a policy prompt outcome or a purchase-flow outcome. The event service accepts only predefined event and property codes. It does not accept names, email addresses, messages, conversation-starter text, photos, report narratives, search text, coordinates, child information or raw profile answers. Account and session references are converted to keyed pseudonyms before storage.
When you reach the public website through a campaign or creator link, Pipe may retain bounded source, campaign, creator, creative and page-variant codes with a keyed pseudonymous website-session token and whether the App Store link was selected. Pipe does not store ad-platform audience membership, parenting status, profile answers, contact details, precise location or a raw IP address in this attribution record.
Crash diagnostics. If error monitoring is enabled, Sentry processes minimized crash, stack, app-build, operating-system and performance information so Pipe can investigate reliability problems. Pipe disables default personal-data collection, screenshots and view-hierarchy capture in the mobile app and filters authentication, message, location, report and profile-answer fields from server diagnostics.
Purchases. If Pipe Plus is offered, Apple or Google processes your store payment information. RevenueCat helps Pipe validate the resulting subscription entitlement and renewal state. Pipe receives a store product identifier, store, environment, expiry or renewal state and a Pipe-specific customer identifier; Pipe does not receive or store your full payment-card details.
3. Google and Apple sign-in
If you choose Google or Apple sign-in, we receive the provider identifier and the limited account information the provider makes available for authentication, such as an email address or name. Pipe does not request access to your Google Drive, contacts, calendar or messages. We use provider data to create, secure and recover your Pipe account and to prevent duplicate or abusive sign-ins.
4. How we use information
- create and secure your account;
- build your profile and provide reciprocal matching, discovery and messaging;
- calculate compatibility using the preferences and broad availability you provide;
- operate verification, moderation, blocking, reporting and fraud prevention;
- send account, safety, match and message notifications according to your settings;
- measure reliability and improve the service using minimized or aggregated data;
- comply with law, enforce our terms and protect members and the public.
We do not sell personal information. We do not use private profile, message, precise-location or Google sign-in data for cross-context behavioral advertising.
5. When information is shared
Other members see only the profile information you publish, approximate location or distance, and interaction information necessary for matching and messaging. We share information with infrastructure, media-processing, email, push-notification, authentication, analytics, store-payment and safety vendors only to operate the service under contractual and security controls.
Persona acts as Pipe's hosted photo-confirmation service provider. Pipe sends a pseudonymous inquiry reference and Persona collects the capture and technical signals needed to perform the configured check. Persona's current processor privacy notice is available at withpersona.com/legal/privacy-policy.
Sentry acts as an error-monitoring service provider when configured. RevenueCat acts as a subscription-entitlement service provider when paid features are enabled. Apple or Google remains the payment processor for a purchase made through its mobile store. Pipe's first-party product-event store remains within Pipe's application database and is not used for cross-context advertising.
We may disclose information when reasonably necessary to comply with law, respond to valid legal process, address suspected fraud or harm, protect rights and safety, or complete a corporate transaction subject to appropriate notice and safeguards. We do not disclose report details to the reported person when doing so would expose a reporter or undermine safety.
6. Retention and deletion
We keep information only for as long as needed for the purposes described above. Account data is retained while your account is active. When you request deletion, your profile is removed from discovery and Pipe begins deletion or irreversible anonymization of eligible data, including media stored with our providers.
Pipe keeps a current photo-confirmation result while it is needed to operate the feature and removes eligible inquiry references, attempts and results through account deletion and scheduled retention. Persona retains hosted capture data according to Pipe's configured provider settings, the notice shown in the hosted flow and applicable legal exceptions. For access or deletion of provider-held verification data, contact [email protected] or use Persona's privacy portal. A Pipe account-deletion request does not override a provider's legally required retention.
Narrow exceptions may apply for security records, fraud prevention, charge or transaction records, report evidence, appeal windows, legal holds and obligations imposed by law. Backups expire on their normal protected rotation and are not restored into active use except for disaster recovery.
First-party pseudonymous product events are kept for up to 13 months and then deleted or aggregated. Operational health samples are kept for 30 days. Crash diagnostics and subscription records follow the configured provider schedule and the period reasonably needed for reliability, entitlement, dispute, accounting and legal purposes. Store transaction history may also remain available through Apple or Google under your store account.
7. Your choices and rights
You can edit profile and preference information, control visibility and notifications, block members, request an export, or delete your account. Depending on where you live, you may also have rights to access, correct, delete, restrict or object to processing, withdraw consent, receive a portable copy, or appeal a denied request. We will verify requests proportionately and will not discriminate against you for exercising a privacy right.
Email [email protected] to exercise a right or ask a privacy question.
8. Adults only
Pipe is only for people aged 18 or older. We do not knowingly permit minors to create accounts. Profile media may not include minors, and members should not publish names, schedules, schools, precise locations or other identifying information about minors. If you believe a minor is using Pipe or identifiable minor information has been posted, report it through the app or email [email protected].
9. Security and international use
We use technical and organizational safeguards including encryption in transit, access controls, scoped service credentials, private media storage and monitoring. No system is completely secure. Because Pipe is available internationally, information may be processed in countries other than your own, including the United States, with safeguards required by applicable law.
10. Changes and contact
We may update this policy as the product, providers or law change. Material changes will be communicated in the app or by another appropriate channel before they take effect when required. Questions may be sent to [email protected].