Privacy Policy
Last updated: 13 August 2026
This policy explains what Blur collects, why, where it is kept and how to erase it. It describes how the service actually works: where you find a technical explanation, it is because that detail changes what happens to your data.
1. Who processes your data
The data controller is [FULL NAME], a natural person, resident at [FULL ADDRESS], tax code [TAX CODE].
For anything concerning your data, write to [PRIVACY EMAIL]. We reply within one month, as required by Regulation (EU) 2016/679 (GDPR).
2. What we collect
What you give us to have an account: email address, password (kept only as a hash, never in clear text), name, date of birth, gender and city.
What makes up your profile: bio, prompt answers, interests, photographs, personality questionnaire answers.
What using the service generates: the messages and voice notes you send, likes and matches, reveal points earned, sign-up and last sign-in dates.
We collect nothing from third parties and buy profiles from nobody.
3. How your photographs are handled
This is what makes Blur different, so it is worth spelling out.
When you upload a photo, the original is kept in a private store that is never publicly reachable. From it the server derives five progressively more legible versions.
The version seen by people who have not unlocked your photo is scaled down to 6% of the original and blurred ten times before being scaled back up. That loss is irreversible: the image no longer contains the pixels of your face, so it cannot be reconstructed, not even by downloading it.
Sharper versions are handed out only when the reveal points earned in that conversation allow it, and the decision is made on the server: your device never receives a version you have not unlocked.
Deleting a photo, or your account, removes the original and every derived version from the store.
4. Voice notes and messages
Voice notes are converted by the server to MP3 so they play on any device, and stored where they can only be reached through an unguessable address.
Text messages and voice notes stay in the conversation for as long as the match exists, and are deleted when the account is closed.
5. Location
If you allow access to your location, the GPS coordinates are used once, immediately, to derive the name of your city through your device's own geocoding service (Apple or Google, depending on the platform).
Only that name — for example «Rome» — reaches our database. The coordinates are neither stored nor sent to our servers.
You can also type your city by hand and never grant the location permission: the service works just the same.
6. Why we process data, and on what basis
To provide the service you asked for — building a profile, showing you people, running conversations and reveals: performance of a contract (Art. 6.1.b GDPR).
To keep the service safe and prevent abuse: legitimate interest (Art. 6.1.f).
For location and push notifications: your consent (Art. 6.1.a), which you can withdraw at any time from your device settings.
We do not use your data for advertising and we sell it to nobody.
7. Who else touches your data
Google Firebase, for authentication (email and password) and for delivering push notifications. Google acts as a processor.
The infrastructure running the database and the file store is operated directly by the controller on dedicated servers; data is not replicated to third-party services.
There are no analytics, advertising trackers or third-party profiling tools, neither in the app nor on this site.
8. How long we keep it
As long as your account exists. We apply no automatic expiry to the content you create.
When you delete your account from the app settings, the erasure is immediate and final: profile, photographs (original and derived versions), voice notes, messages, likes, matches and questionnaire answers are removed. We keep no copies and there is no grace period.
Deleting the account asks for your password: that is what stops somebody else from erasing your profile.
9. Your rights
You can ask to access your data, correct it, erase it, restrict its processing, receive it in a machine-readable format, and object to certain processing.
Write to [PRIVACY EMAIL] to exercise them. If you believe your rights have not been respected, you may lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or your local supervisory authority.
10. Minimum age
Blur is for adults. Registration asks for your date of birth and accounts for people under 18 are not created. If we learn that an account belongs to a minor, we delete it.
11. Changes to this policy
If we change how we handle data, we update this page and the date at the top. If the change is substantial we tell you in the app before it takes effect.
This text describes the technical behaviour of the service faithfully. The bracketed references must be completed with the controller's details, and the whole document should be reviewed by a lawyer before publication.