Privacy notice
This notice covers this website, peony.social, and the
Peony app.
The app is not open yet. The sections about it describe what it does with your data when it launches, so that you can read them before deciding to join rather than afterwards. Nothing in the app is collecting anything from you today.
Who is the controller
Alsanthea Ltd, a company registered in England and Wales (company number 17419177), registered office 124 City Road, London, United Kingdom, EC1V 2NX, is the controller for the personal data described here. Peony is one of its products, and we are registered with the Information Commissioner's Office.
Data protection enquiries: privacy@peony.social. We answer within one month.
Who this covers
Peony launches in London, and at launch the app is offered in the United Kingdom. UK data protection law applies to everything described here. If we open somewhere else, we will say so here before we do.
This website
This site sets no cookies, runs no JavaScript, embeds no third-party content and uses no analytics service. Nothing follows you from this site to anywhere else, and we have not asked you to consent to anything because there is nothing to consent to.
Our content delivery network records a standard server log entry for each request: your IP address, the time, the page requested, the response, your browser's user-agent string, and the page you arrived from if your browser sent one. Logs exist to keep the site available, diagnose faults and identify abuse such as denial-of-service traffic; the lawful basis is our legitimate interest in running a secure and functioning website, and they are deleted automatically after 90 days. We do not use them to build a profile of you and we do not try to identify visitors.
If you write to one of the addresses on the support page, we hold that message and your email address so we can answer it — our legitimate interest in replying to the person who wrote to us. It is kept while it is relevant and then deleted.
The app
Almost all of this is data you have to give us for the app to do what it says: a dating app that arranges a real meeting cannot work without knowing who you are, when you are free and roughly where you are. Unless a section says otherwise, the lawful basis is performance of our contract with you — the terms you accept when you create an account.
The short version, in one table
Everything the app holds, why, and on what basis. Each row is expanded in a section below.
| Why | What | On what basis |
|---|---|---|
| Creating and securing your account | Mobile number, Apple or Google sign-in identifier, a token and a key per device | Our contract with you; our legitimate interest in keeping fake accounts out |
| Checking you are over 18, and real | The verification result, your legal name and your verified date of birth | Legal obligation; our legitimate interest in an adults-only service |
| Showing you to a match, and them to you | Display name, age, gender, who you want to meet, bio, photographs, and the snapshot pinned at confirmation | Our contract with you |
| Offering dates you can actually make | Your availability, your notice period and horizon, and calendar free/busy times | Our contract with you; consent for the calendar |
| Choosing a meeting point that is fair to both | Your single home point | Our contract with you |
| Knowing whether people turned up | Whether you arrived near the meeting point around the date, and how accurate the reading was | Our contract with you; our legitimate interest in handling no-shows fairly |
| Helping you find each other on the day | Your live location, while the date runs | Consent |
| The activity badge | The weekly exercise energy your phone has recorded, and the level from it | Explicit consent (health data) |
| The STI badge | That a current test exists, its date, and which service issued it — never the results | Explicit consent (health data) |
| Feedback, and acting on reports | Star ratings, the answers you pick, anything you type, and what you tell us at abuse@ | Our contract with you; our legitimate interest in keeping people safe |
| Keeping you away from people you know | A one-way hash of the numbers you choose | Consent |
| Stopping a blocked account coming straight back | A one-way hash of your own number, for 183 days after you delete the account — never the number | Our legitimate interest in keeping removed and blocked people out |
| Taking payment | Purchases, and every movement of tokens in your balance | Our contract with you; legal obligation (accounting and tax) |
| Telling you about a match or a date | A push token per device; your number, for SMS | Our contract with you |
| Keeping the service working | Server logs and scrubbed crash reports | Our legitimate interest in a service that runs |
Your account
We hold your mobile number, which is how an account is identified, and a record of when it was created. Signing in sends a one-time code by SMS; we keep a hash of that code, never the code itself, and it expires in minutes. If you sign in with Apple or Google instead, we keep the identifier those services give us — not your password, and not your address book.
We also keep a token for each device you are signed in on, and a key the device uses to prove it is a genuine phone rather than a script. That is our legitimate interest in keeping fake accounts out of a service whose whole premise is that the other person is real.
Proving you are over 18, and a real person
Verification is carried out by Stripe Identity. You show them an identity document and a photograph of your face; they process those and tell us the outcome. What we store is the result, your legal first and last name and your verified date of birth — not the document, and not the selfie.
The lawful basis is our legal obligation and our legitimate interest in keeping under-18s out of an adults-only service and in making an account traceable if something goes badly wrong. Without it you cannot use the app; that is deliberate and it is the point.
Your profile
A display name, your age, your gender, who you want to meet, an optional short bio, and your photographs. Photographs are stored by us, in the United Kingdom — not on a third-party image host. When a date is confirmed we keep a snapshot of the profile your match saw, so that what was shown to them cannot be quietly changed afterwards.
When you are free
The times you mark as available, how much notice you want and how far ahead you are willing to plan. If you connect a calendar, we read free/busy times only — the start and end of things you are busy for. We do not receive, and could not show you, the titles of your events, who is attending them, or where they are. Connecting a calendar is optional and runs on your consent, which you can withdraw by disconnecting it.
Where you are
You drop a single home point on a map when you join. It is used for one thing: choosing a meeting point that is a fair journey for both people, and knowing which city you are in. It is not a live location, we do not track you with it, and no other member ever sees it.
Around the time of a date — and only then — the app checks whether you actually arrived at the meeting point, and keeps the answer together with how accurate the reading was. That is what stops a no-show becoming your word against theirs. During a date you may additionally choose to share your live location with the person you are meeting so you can find each other; that is your consent, it is off unless you turn it on, and it stops when the date does.
Badges, and the health data behind two of them
Most badges are derived from what has already happened: whether you have cancelled or not turned up, and whether the people you met said it went well. Two are different, and both are special category health data, so both are optional and both run on your explicit consent:
- Activity level. If you turn it on, we read the exercise energy your phone has recorded — from Apple Health or Google's Health Connect — and keep a weekly figure and the level derived from it. Not your workouts, your heart rate, your steps or anything else in there.
- STI reported. If you choose to show a test result, we read it, and keep the fact that a current test exists, its date and which service issued it. We do not store the results themselves, and no other member is shown anything but the badge.
You can withdraw either consent in the app, which removes the badge and the data behind it.
Dates, and what happens afterwards
The dates you are offered and agree to, their time and meeting point, whether you said you were running late, any note the two of you exchanged about the meeting, whether you arrived, and what you each said afterwards — the star ratings, the answers about the meeting point, and anything you typed. Ratings are private: the other person never sees what you said about them, and vice versa.
If you ask us to keep you apart from people you already know, we store a one-way hash of the phone numbers — enough to recognise a number we are shown again, not enough to reconstruct anyone's contacts. Contact details you choose to swap after a date are held so the app can show them to the person you swapped with.
Paying
Payments run through Stripe, or through Apple's or Google's in-app purchase systems. We never see or hold your card number. We keep a record of each purchase and each movement of tokens in your balance — what it was for, when, and how much — because that is our record of the contract and we are required to keep accounting records.
Messages and diagnostics
We keep a push-notification token per device so the app can tell you about a match or a date. We send SMS through Twilio. When the app or our servers hit an error, a crash report goes to Sentry, which we run in its EU region. Those reports carry an account identifier and technical detail — which screen, which request, what broke — so we can tell whether a fault hit one person or everybody. They are scrubbed of names, contact details, photographs, locations, health data and the contents of messages, and screen recording is switched off. Keeping the service working is our legitimate interest.
What other members see about you
This is the part most notices leave out. Before a date is agreed, the other person sees no profile at all — only the time, the meeting point and your badges. Two hours before the date, and not before, they see your first name, your age and your photographs, so that you can recognise each other. Nobody can browse, search for, or collect members, because there is nothing to browse.
Who else processes it
Amazon Web Services (hosting, in the United Kingdom), Google Workspace (our email), Stripe and Stripe Identity (payments and verification), Apple and Google (sign-in, in-app purchases and push notifications), Twilio (SMS) and Sentry (error reports). Each processes this data on our instructions and for no purpose of their own. We do not sell personal data, we do not share it for advertising, and we pass it to no one else except where the law requires it or to protect someone from harm.
Where it is held
Your account, your photographs and everything about your dates are stored in the United Kingdom. Sentry is in the EU. Our content delivery network serves pages from locations worldwide, so a request may be logged at an edge location outside the UK before the record is consolidated.
Some data reaches the United States. Stripe and Twilio are certified under the UK Extension to the EU–US Data Privacy Framework, which UK law recognises as protecting personal data to the standard it requires, and that is the basis on which their share of it goes. For Apple and Google — sign-in, in-app purchases and push notifications — we rely on the data-protection terms in their developer agreements, which carry the UK's standard contractual clauses where the Framework does not apply.
How we protect it
Everything between your phone and us travels over an encrypted connection, and nothing is accepted over an unencrypted one. The database and the store holding your photographs are encrypted at rest with keys we manage ourselves; backups are encrypted too and are kept for 30 days. Your photographs sit in our own storage rather than on a third-party image host.
The app proves to us that it is a real app on a real phone before it can act on your account, which is what keeps scripted sign-ups out of a service whose premise is that the other person is real. Crash reports are stripped of personal content before they leave the device, and screen recording is switched off. Access to production data is limited to the people who run the service, and it is logged.
No system is perfectly secure, and we would rather say so than imply otherwise. If you find a weakness, security@peony.social and our security.txt are the fastest routes to someone who can fix it.
How long we keep it
Your account data is kept while your account exists, and you can delete your account in the app at any time, without asking us and without giving a reason.
| Website server logs | 90 days |
| App server logs | 90 days |
| Database backups | 30 days |
| Letters and emails you send us | While the matter is open, then deleted |
| Crash reports | The period our error-reporting plan retains them, then deleted automatically |
| Your account, profile, photographs, contacts and availability | Until you delete your account |
| Records of dates that have happened | Kept after you leave, emptied of your profile — below |
| A one-way hash of your phone number, after you delete | 183 days (about six months), then deleted |
| Purchases and token movements | Six years, which is what tax law requires |
Deleting it removes your photographs, your profile, your contact details, your availability and the list of people you asked to be kept away from. We do not keep your phone number — but we do keep a one-way hash of it for 183 days — about six months — which is enough to recognise the same number if it comes back and not enough to reconstruct it. That is what stops an account that was blocked, or removed while a report stood against it, from returning the next morning on the same number. After that it is deleted, and the number is as free as any other.
Two things outlive the account, and it is fairer to say so than to let you discover it later. The dates you have already had are kept, emptied of your profile: the other person's own history — their badges, their record of turning up — must not silently change because you left, and the snapshot of your profile that was pinned when you met is kept for the same reason and is not shown to them again. And purchases and token movements are kept for six years, which is what tax law requires of us.
Decisions made automatically
Matching is automatic: the app pairs people by availability and by what each has said they are looking for, and picks the meeting point by distance. Badges are calculated, not awarded by a person. None of that has a legal effect on you, and none of it is based on profiling your personality. A decision to suspend or remove an account is made by a person, and you can write to privacy@peony.social to contest one.
Your rights
You can ask us for a copy of the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on your consent — the health data behind two badges, calendar access, sharing your location during a date — you can withdraw it at any time, in the app, without affecting what was done while it was in force.
Write to privacy@peony.social and we will respond within one month.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather you gave us the chance to put it right first.
Children's privacy
Peony is for adults, and nobody under 18 can use it. Age is verified against an identity document rather than declared, which is the point of the verification step above; an account we find belongs to someone under 18 is closed. We do not knowingly collect personal data from anyone under 18, and if you believe we have, write to privacy@peony.social and we will delete it.
Changes
If we change what we collect or what we do with it, we will update this notice and the date below, and tell you in the app where the change is one you would want to know about. This notice was last updated on 23 September 2026.