Privacy Policy
Effective date: 1 August 2026 · Version 1.0 (pre-launch)
Talora ("Talora," "we," "us," or "our") is a mobile dating application built around one or two considered introductions a day, human-verified profiles, and photos that reveal gradually as trust builds. This policy explains what personal data we collect, why, how long we keep it, who we share it with, and the rights you have over it — both on this website and, once it is live, in the Talora app.
This is our pre-launch policy. It is drafted to the standard we intend to operate at from day one, and will be reviewed by qualified legal counsel in our jurisdiction before the app opens to the public. If you have questions in the meantime, see Contact us.
1. Scope and who we are
Talora is the data controller for the personal data described in this policy. This policy covers two things: the marketing website at trytalora.com, which exists today to describe Talora ahead of launch, and the Talora mobile app, which is not yet publicly available. Where a practice applies only to the app once it launches, we say so explicitly.
We operate out of, and store user data in, the European Union. If you are located outside the EU/EEA, your data may still be processed in the EU as described in Section 8.
2. Information we collect
The categories below describe what the Talora app will collect once it launches. Nothing in this section is collected by the current marketing website — see Section 3 for what applies today.
Name, date of birth, gender and the genders you're interested in, a short bio, interests, and the photos you upload.
An in-app camera capture and a short spoken sentence, taken at signup to confirm you're a real, live person. This is used to generate a verification decision and is not shown to other users.
Approximate location, used to find nearby matches and shown to matches only as a rounded distance (e.g. "2.1 km"), never an exact point or address.
The content of conversations with your matches, and anything you submit when you report or block another user.
If you purchase a paid plan, our payment processor handles your card details directly — we never see or store full card numbers. We retain a record of the transaction (plan, amount, date) for accounting and support purposes.
Device type, operating system version, app version, crash and performance diagnostics, and push-notification tokens.
3. This website, specifically
trytalora.com, the site you're reading this on, does not run analytics, does not set tracking or advertising cookies, and has no sign-up form. It doesn't collect anything from you beyond what any web server sees by default: our hosting provider processes standard technical logs (IP address, browser type, request timestamps) for security and reliability, and typically retains them for a short, rolling window. We don't have access to, or make use of, that log data ourselves.
4. How we use your information
Once the app is live, we use the data described above to:
- Create and maintain your account and profile.
- Select your daily match or matches, and run the progressive photo reveal as a conversation develops.
- Verify that your account belongs to a real person, and screen photos and voice clips for AI-generated or deepfaked media.
- Screen the first messages of a new match for known scam patterns — phone numbers, wallet addresses, IBANs, and links — and hold them back until you've reached the reveal.
- Review reports and blocks, and take action against accounts that break our rules.
- Process payments for paid plans.
- Send you service notifications (a new match, a new message) and, if you've agreed to receive them, occasional product updates.
- Maintain the security, stability, and integrity of the service, including diagnosing crashes and abuse.
- Comply with legal obligations that apply to us.
We do not use your data to train third-party AI models, and we do not sell your personal data.
5. Our legal bases for processing
Where the UK/EU GDPR applies, we rely on the following legal bases:
- Performance of a contract — creating your account, matching, messaging, and billing.
- Legitimate interests — fraud and scam prevention, service security, and improving the product, balanced against your right to privacy.
- Legal obligation — record-keeping, responding to lawful requests from authorities, and tax/accounting requirements.
- Consent — optional features, such as marketing communications, that we ask you to opt into separately, and that you can withdraw at any time.
6. Automated processing and AI
We use automated systems narrowly, to keep the service safe — never to write, suggest, or embellish anything on your behalf.
- No generative AI in profiles or messages. No smart replies, no AI icebreakers, no auto-complete. We never run AI-authorship detectors on your messages either.
- Media authenticity screening. Photos and voice clips are automatically screened for signs of AI generation or deepfakes before they reach another user.
- Scam-intent screening. Automated pattern-matching flags likely scam content (contact details, payment requests, links) in the first messages of a new match — the highest-risk window. Established conversations aren't screened.
- Human review, not automated bans. Reports land in a queue actioned by a person. We do not make final enforcement decisions — suspending or banning an account — by algorithm alone.
Any expansion in scope of automated processing will be reflected in this policy before it ships.
8. International data transfers
Our infrastructure is based in the EU. If a service provider we use processes data outside the EU/EEA, we put appropriate safeguards in place first — such as the European Commission's Standard Contractual Clauses — to keep the same level of protection your data has under this policy.
9. Data retention
We keep personal data only as long as we need it for the purposes it was collected for. As a general guide: account and profile data for as long as your account is active, plus a limited window afterward in case you return; verification media only as long as needed to make and audit a verification decision; billing records for as long as required by tax and accounting law; and report/moderation records for as long as needed to enforce our rules and defend against disputes. When data is no longer needed, we delete or anonymize it.
10. Security
We encrypt data in transit and at rest, restrict internal access to what each system and team member needs to do their job, and keep contact details (beyond a first name and approximate distance) hidden from matches until you've progressed the conversation. No system is perfectly secure, and we can't guarantee absolute security — but we treat it as a first-class requirement, not an afterthought.
11. Your rights
If the UK/EU GDPR applies to you, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request erasure of your data ("right to be forgotten"), subject to legal retention requirements.
- Restrict or object to certain processing.
- Receive your data in a portable format, or have it transferred directly to another provider where technically feasible.
- Withdraw consent at any time, where we rely on it.
- Lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, contact us using the details in Section 15. We'll respond within the timeframes required by applicable law.
12. Children
Talora is for adults only. You must be at least 18 years old to use it, and our verification step is designed, in part, to help enforce that. We don't knowingly collect data from anyone under 18; if we learn that we have, we'll delete it.
14. Changes to this policy
We'll update this policy as the product develops. For material changes, we'll update the effective date above and, once accounts exist, notify you directly before the changes take effect.
15. Contact us
Questions, requests, or complaints about this policy or your data can be sent to privacy@trytalora.com. We aim to acknowledge every request within 5 business days.