Yoked Privacy Policy & Biometric Data Consent Notice
PART 1 — PRIVACY POLICY YOKED PRIVACY POLICY
Last updated: June 29, 2026
1. Introduction
Yoked Limited ("Yoked", "we", "us", "our"), a company incorporated in Hong Kong, respects your privacy. This Privacy Policy explains what personal data we collect, how and why we use it, who we share it with, and the choices and rights you have. It should be read together with our Terms of Service, our Community Guidelines, and our Biometric Data Consent Notice.
We are the data controller (in terms of the Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”), the "data user") responsible for your personal data. Our contact details are in §16.
This Policy is designed to comply with the PDPO and, where they apply to you, the General Data Protection Regulation of the European Union / United Kingdom (“EU GDPR” / “UK GDPR”), the California Consumer Privacy Act (“CCPA”), the California Privacy Rights Act (“CPRA”), the Illinois Biometric Information Privacy Act ("BIPA") and comparable US state biometric laws, and other applicable data-protection laws.
2. Who this applies to
The Service is for adults aged 18 or over. We do not knowingly collect personal data from anyone under 18; if we learn we have, we will delete it.
3. Personal data we collect
(a) Information you provide, including:
- Registration: name, email address, phone number, date of birth, gender, and login credentials.
- Profile: photographs, bio, interests, relationship preferences, the gender(s) of people you wish to meet, and any other details you choose to add. Some of this can reveal sensitive information — see §4.
- Verification (required for matchmaking): to be matched with other users, you must complete our liveness-based photo verification, which involves submitting a real-time selfie. You can use non-matchmaking features of the app without verifying. The selfie image is used only to run the check and is then deleted; certain facial
measurements (biometric data) derived from it may be retained — see §4 and our Biometric Data Consent Notice.
- Subscriptions: processed through third-party app stores and/or payment processors. We receive limited transaction data (e.g., that a payment succeeded, the plan, and partial card details). We do not store full payment-card numbers.
- Communications: messages you send through the Service, and your correspondence with our support team.
- Reports and appeals: information you give us when you report another user or content, or appeal a decision.
(b) Information we collect automatically, including:
- Usage data: profiles viewed, likes, matches, features used, and messaging metadata.
- Device and technical data: IP address, device identifiers, device type, operating system, app version, and crash/diagnostic logs.
- Location: approximate location derived from your IP address and, with your permission, more precise device location.
- Cookies and similar technologies (see §12).
(c) Information from third parties, including:
- Third-party logins (e.g., Apple, Google, Facebook): the basic profile information you authorise them to share.
- Service providers such as analytics, fraud-prevention, and payment partners.
(d) Information we generate, including:
- Automated screening signals and flags (see §6) and matching/recommendation outputs.
4. Sensitive / special-category data, including biometric data
(a) Sensitive profile information. Using a matchmaking service inevitably involves information that may be treated as sensitive, such as data revealing your religion, ethnicity, or health if you choose to share them. Where the law requires it (including GDPR Article 9), we process this information on the basis of your explicit consent, for the purpose of providing the Service. By continuing to use the Service, you explicitly consent to our processing of your sensitive profile information. You can withdraw consent by removing the relevant information or deleting your account.
(b) Biometric data from photo verification. Photo verification is required to access matchmaking — that is, to be matched with, and to match with, other users. It is not required to
use other features of the app (e.g. [example]). If you choose to access matchmaking, you take a real-time selfie, and our system performs a "liveness" check and compares the selfie against your profile photos to assess whether the account is operated by a real, live person who matches those photos. To do this, the system derives facial measurements (biometric data) from the selfie. We require this only because verifying that a real, live person is behind each profile is necessary to protect the integrity and safety of matchmaking and to combat fake accounts, impersonation, and ban evasion.
- The selfie image is deleted after the check is completed.
- The facial measurements may be retained and used for the limited trust-and-safety purposes described in our Biometric Data Consent Notice, in accordance with a published retention and destruction schedule.
- The feature does not check any government-issued identity document and does not verify your legal name, identity, age, or any other attribute. It is not an identity or background check.
We process biometric data only on the basis of your separate, explicit, written consent (see the Biometric Data Consent Notice), as required by GDPR Article 9 and biometric-privacy laws such as the Biometric Information Privacy Act of the state of Illinois of the United States (“BIPA”). We do not sell, lease, trade, or otherwise profit from your biometric data. You may withdraw consent at any time as described in that Notice.
5. How we use your data, and our legal bases
Where the GDPR applies, our legal bases are shown below; where the PDPO applies, we use data for the purposes for which it was collected and directly related purposes.
Purpose Legal basis (GDPR)
Create your account and provide the Performance of our contract with you matching service
Liveness-based photo verification, as a Your explicit consent (Art. 9(2)(a)); supported by condition of accessing matchmaking our legitimate interest in the integrity and safety of matchmaking
Safety, moderation, fraud prevention, Legitimate interests; legal obligation; and, for automated screening, and enforcing our sensitive data, substantial public interest / your Terms consent
Process and manage subscriptions and Performance of contract; legal obligation keep financial records
Send service and transactional messages Performance of contract
Send marketing / promotional messages Your consent (you may opt out at any time)
Improve, secure, and develop the Service Legitimate interests (and consent for non-essential analytics)
Comply with law and respond to lawful Legal obligation requests
6. Automated decision-making and AI screening
We use automated tools, including machine learning, to (a) power matching and recommendations, and (b) detect behavioural and account signals indicating policy violations, fake or fraudulent accounts, spam, abusive or troll-like behaviour, and attempts at ban evasion or re-registration by previously removed users.
These tools are limited and imperfect. Where an automated process could lead to a decision that significantly affects you (such as suspension or a ban), a human reviews the decision on request and you can appeal (see Terms §16.4). We do not subject you to solely-automated decisions producing legal or similarly significant effects without the safeguards required by Article 22 GDPR where it applies.
We do not use automated tools to diagnose, infer, or label your mental or physical health.
7. How we share your data
- With other users: your profile and the content you choose to share are visible to other users, as designed.
- With service providers (processors): hosting, analytics, payments, fraud-prevention, customer support, and moderation partners — under contract and only as needed to provide the Service.
- For legal and safety reasons: to comply with applicable law, respond to lawful requests, enforce our Terms, prevent fraud, or protect the rights, property, or safety of users, the public, or us.
- With your consent: any other disclosure.
We do not disclose your biometric data except to processors acting on our behalf under contract, or where disclosure is required by law — and never for sale or profit (see §4 and the Biometric Data Consent Notice).
8. We do not sell your personal data
For as long as we own and control the Service, we do not and will not sell, rent, or trade your personal data, and we do not "sell" or "share" your personal data for cross-context
behavioural advertising as those terms are defined under California law. A change in the ownership or control of our business is governed by §9.
9. Business transfers — what happens if we are acquired or sold
Our commitment in §8 applies while the Service remains under our ownership and control. If we become involved in a merger, acquisition, investment, financing, reorganisation, or a sale of all or part of our business or assets, and that transaction would involve transferring your personal data to another entity, we will require that other entity to comply with the terms of this Privacy Policy. We will further notify you in advance and ask for your consent before your personal data is transferred to the acquiring entity, and you will have the opportunity to opt-out from such transfer and request for your personal data to be deleted within a reasonable time. We will not sell your personal data as a standalone product.
10. International data transfers
We store and process personal data in [HOSTING LOCATION(S)]. If you are located elsewhere, your data may be transferred internationally. For transfers from the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or an adequacy decision. For any future mainland-China users, separate cross-border transfer rules under the Personal Information Protection Law (“PIPL”) will apply.
11. Data retention
We keep your personal data while your account is active and for as long as needed for the purposes in this Policy. After you delete your account, we delete or anonymise your personal data within [X days], except data we must retain for legal, accounting, safety, fraud-prevention, or dispute-resolution purposes.
- Verification selfies are deleted after the verification check is completed.
- Biometric measurements are retained only for the period set out in our Biometric Data Consent Notice and are then permanently destroyed.
- We may retain limited information about banned or removed users to enforce bans and prevent re-registration, and to keep our community safe.
12. Cookies and similar technologies
We use cookies and similar technologies to operate, secure, and improve the Service and to remember your preferences. You can control non-essential cookies through [your
device/browser settings / our cookie banner]. [Add a separate Cookie Policy if you use analytics/advertising technologies.]
13. Security
We use reasonable technical and organisational measures designed to protect your personal data, including [encryption in transit, access controls, etc.]. We protect biometric data using a reasonable standard of care that is at least as protective as the way we handle other confidential and sensitive information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
14. Your rights
Depending on where you live, you may have some or all of these rights: to access your data; to correct inaccurate data; to delete your data; to port your data; to object to or restrict certain processing; to withdraw consent (including biometric consent); and to not be discriminated against for exercising your rights. We do not sell personal data, so there is nothing to opt out of in that respect. To exercise any right, contact us at [PRIVACY CONTACT]; we may need to verify your identity. You also have the right to complain to your local data-protection authority (in Hong Kong, the Privacy Commissioner for Personal Data (PCPD)).
15. Region-specific disclosures
- Hong Kong (PDPO): You have the right to request access to and correction of your personal data. Direct marketing: we will not use your personal data in direct marketing without your consent, and every marketing message will offer an opt-out.
- EEA / UK (GDPR): Legal bases are set out in §5; you may lodge a complaint with a supervisory authority; [our EU/UK representative, if appointed, is [NAME/CONTACT]].
- California (CCPA/CPRA): We disclose the categories of personal information we collect (§3) and the purposes (§5); we do not sell or share personal information; you may exercise your rights under §14, including the right to limit use of sensitive personal information.
- Illinois and other US biometric laws (BIPA etc.): Our collection, use, retention, and destruction of biometric data, and your written consent, are described in §4 and in our Biometric Data Consent Notice. We do not sell, lease, trade, or profit from biometric data.
- Mainland China (future): A separate PIPL-compliant notice, consent, and localisation arrangement will apply before any mainland launch.
16. Contact
Questions or requests: [PRIVACY/DPO CONTACT EMAIL], or [LEGAL ENTITY NAME], [ADDRESS].
17. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will give reasonable notice (e.g., in-app or by email) before they take effect.
PART 2 — COMMUNITY GUIDELINES [APP NAME] COMMUNITY GUIDELINES
Last updated: May 30, 2026
These Guidelines work alongside our Terms of Service. They exist to keep Yoked a respectful, genuine, and safe place to meet people. Breaking them can lead to content removal, a warning, suspension, or a permanent ban. Where a decision significantly affects your account, a human will review it on request and you can appeal.
Be real Use your own recent photos, your real age, and accurate information about yourself. One person, one account. No impersonating anyone else, no fake or bot profiles, and no creating a new account to get around a ban.
Be respectful Treat people the way you'd want to be treated. No harassment, bullying, threats, intimidation, or stalking — including repeatedly contacting someone after they've stopped responding, unmatched, or asked you to stop. No hate speech or content that attacks or demeans people based on race, ethnicity, national origin, religion, disability, gender, age, or other protected characteristics.
Keep it non-commercial Yoked is for meeting people, not for business. No advertising, promotion, soliciting money or gifts, fundraising, multi-level marketing, or directing people to other platforms or paid services. No escorting, sex work, or any transactional sexual services.
No scams or fraud Never ask other users for money, financial help, gift cards, crypto, or banking/identity details, and never offer "investment opportunities." Romance scams, phishing, and "catfishing" lead to an immediate ban — and we encourage you to report them.
Respect consent and privacy Don't share, post, or threaten to share someone's private information, private messages, or intimate images without their consent. No "doxxing." Don't record or screenshot private conversations to harass or expose someone.
Adults only, and protect minors Yoked is strictly 18+. Any attempt to use the app while under 18, to contact a minor, or to share sexual content involving minors will be removed and reported to the appropriate authorities, in which case, we may share your personal data with such appropriate authorities in accordance with §7 of our Privacy Policy
No sexual content or nudity Yoked does not allow any sexual content or nudity anywhere on the app. Photos must not show nudity, swimwear, underwear, or similarly revealing clothing. Do not post sexually explicit or suggestive content, and do not send sexual messages, images, or other material to anyone — solicited or not. Non-consensual intimate imagery and "revenge porn" are never allowed and may be reported to the appropriate authorities, in which case, we may share your personal data with such appropriate authorities in accordance with §7 of our Privacy Policy.
Keep it legal No promoting or arranging anything illegal — including illegal drugs, weapons, violence, terrorism or violent extremism, human trafficking, or self-harm and suicide content. If you or someone else may be in danger, contact local emergency services.
Play fair with the platform No spamming, mass-messaging, scraping, bots, hacking, or trying to bypass our safety or security features.
Stay safe when you meet people
To be matched with other users, everyone must pass our photo verification — a liveness and photo-match check that confirms a real, live person matching the profile photos. It does not confirm who someone actually is, their name, or their age, and we don't run criminal background checks. So even with everyone verified: keep chats on the app until you're comfortable; never send money; meet in public the first time; tell a friend your plans; arrange your own transport; and trust your instincts. Block and report anyone who makes you uncomfortable.
Reporting and consequences You can report a profile, message, or behaviour using [in-app report tool] or [SUPPORT EMAIL]. We review reports but can't promise a specific outcome or timeframe. Depending on severity, we may warn, remove content, suspend, or permanently ban — and serious cases may be reported to law enforcement. If you think we got it wrong, you can appeal at [APPEALS CONTACT].
PART 3 — BIOMETRIC DATA CONSENT NOTICE
[APP NAME] BIOMETRIC DATA CONSENT NOTICE AND RELEASE Last updated: May 26, 2026
This Notice explains how Yoked Limited ("we", "us", "our") collects and uses biometric data when you choose to use our photo verification feature. It supplements our Privacy Policy and Terms of Service. Please read it before giving consent. Verification is required to use our matchmaking features (to be matched with other users), but not to use the app's other features. Please read this Notice before giving consent.
1. What this feature does
To be matched with other users, you must verify. When you do, you take a real-time selfie, and our system performs a "liveness" check (to confirm a real, live person is present) and compares the selfie against your profile photographs to assess whether the account is operated by the person shown in those photos. To do this, our technology creates facial measurements — a mathematical representation of facial geometry derived from your selfie. These facial measurements are "biometric data" (and may be "biometric identifiers" or "biometric information" under laws such as the Illinois Biometric Information Privacy Act, "BIPA").
2. What this feature does NOT do
This feature does not check any government-issued identity document, and it does not verify your legal name, identity, age, or any other attribute. It is not an identity check, not a criminal background check, and not a guarantee that any user is who they claim to be, is safe, or is acting in good faith.
3. What we collect and what we delete
- Selfie image: used only to perform the liveness and photo-match check, and then deleted.
- Facial measurements (biometric data): retained after the selfie is deleted, and used only for the limited purposes in §4, in accordance with the retention and destruction schedule in §6.
4. Why we collect it (purpose)
We collect and use your biometric data solely to: (a) confirm that a real, live person is using the account and that they match the profile photos; (b) issue or maintain a verification badge or similar indicator; and (c) support trust and safety, including detecting and preventing fake or fraudulent accounts, impersonation, and ban evasion or re-registration by previously removed users. We will not use your biometric data for any other purpose without your further consent.
5. We do not sell or profit from your biometric data
We do not sell, lease, trade, or otherwise profit from your biometric data. We do not disclose your biometric data to any third party except: (a) to service providers who process it on our behalf, under contract and only for the purposes above; (b) where you give consent; or (c) where required by law or valid legal process. We protect biometric data using a reasonable standard of care that is at least as protective as the way we handle other confidential and sensitive information.
6. How long we keep it (retention and destruction schedule)
We will permanently destroy your biometric data on the earliest of: (a) when the purpose for collecting it has been satisfied — for example, [when your account is deleted / when your verification is revoked]; (b) [RETENTION PERIOD — e.g., within X days/months] after your last interaction with us; or (c) the maximum period permitted by applicable law (under BIPA, no later than 3 years after your last interaction with us). [Insert your specific period(s). Under BIPA this published schedule is mandatory.]
7. Your consent, and what it's a condition of
We collect and store your biometric data only with your consent, which we ask you to give by the affirmative action described in §9.
Verification is required to access matchmaking. If you do not consent, you can still use the app's non-matchmaking features, but you will not be able to be matched with, or match with, other users. We require verification for matchmaking only because confirming that a real, live person is behind each profile is necessary to protect the safety and integrity of matchmaking.
You may withdraw your consent at any time by [contacting us at [PRIVACY CONTACT] / using the in-app setting]. If you withdraw consent, we will stop using your biometric data and destroy it in line with §6, you will lose access to matchmaking and any verification badge, and you may continue using the app's non-matchmaking features. Withdrawing consent does not affect any processing carried out before withdrawal.
8. Your rights
Depending on where you live, you have rights over your personal data, including biometric data — see the Privacy Policy (§14). For EEA/UK users, we rely on your explicit consent under GDPR Article 9 to process this special-category data. You may also contact your local data-protection authority (in Hong Kong, the PCPD).
9. Consent and release
By selecting [I AGREE / the verification "Continue" button], you confirm that:
- you have read and understood this Biometric Data Consent Notice;
- you consent to our collection, use, storage, and (per §6) destruction of your biometric data (facial measurements) as described here, and to the temporary processing and deletion of your verification selfie; and
- you authorise and release us and our authorised service providers to collect, store, and use your biometric data for the purposes in §4.
This is a written release for the purposes of BIPA and explicit consent for the purposes of the GDPR and other applicable laws.
10. Contact
Questions or to withdraw consent: [PRIVACY/DPO CONTACT EMAIL], or Yoked Limited, [ADDRESS].