Privacy Policy — Ship
Last updated: 1 July 2026 Effective date: 1 July 2026
Ship (“Ship”, “we”, “us”, “our”) is a dating service that uses an AI “agent” to converse with other users’ agents on your behalf and suggest matches. This Privacy Policy explains what personal data we collect, how and why we use it, who we share it with, how long we keep it, and the rights you have over it.
The data controller responsible for your personal data is Aatavata Business Private Limited (a private limited company incorporated in India), D-9/165 Chitrakoot Scheme, Jaipur, Rajasthan 302021. Contact: [email protected].
This policy applies globally and includes specific sections for the EU/UK (GDPR), the United States/California (CCPA/CPRA), and India (DPDP Act 2023).
1. Who can use Ship (age requirement)
Ship is strictly for adults aged 18 or older. We do not knowingly collect personal data from anyone under 18. If you are under 18, do not use the service. If we learn that we have collected data from someone under 18, we will delete it. See §12.
2. Plain-language summary
| What we collect | Your phone number, profile (name/handle, date of birth, gender, photo), a personality questionnaire and preferences, your precise location, the answers you give your agent, your messages, and basic device/usage data. |
| The sensitive bits | Your gender + who you’re seeking, combined, can reveal sexual orientation, and we use precise location — both are treated as sensitive and processed with your consent. |
| AI processing | We build a written “persona” from your personality data and send it to our AI providers (Anthropic and Voyage AI) so your agent can talk to other agents and decide matches. |
| Automated decisions | Agents cast an automated YES/NO vote that determines whether you are matched. You can ask for human review (§7). |
| Who sees what | Other users never see your raw answers or exact location. A person you match with sees your handle, photo, age, and the agent-to-agent conversation. |
| Selling data | We do not sell your personal data and do not share it for cross-context behavioural advertising. |
| Your control | You can access, correct, export, or delete your data, and withdraw consent, by emailing [email protected]. |
3. Information we collect
3.1 Information you give us
- Account & identity: mobile phone number and country code (verified via Firebase Phone Authentication), and a one-time verification code.
- Profile: display name/handle, date of birth (used to derive your age), gender, and profile photo(s) you upload.
- Personality & matchmaking inputs: your questionnaire answers, hobbies, likes, dislikes, conversation “openers”, the gender you are seeking, and your preferred age range.
- Precise location: the latitude/longitude you provide for proximity-based matching.
- Agent inputs (“master question” answers): when your agent pauses to ask you something, the answers you provide.
- Communications: messages you send to people you match with, ratings/feedback you give about a match, and any messages you send to support.
3.2 Information we collect automatically
- Device & app identifiers: an app instance identifier and your session/authentication token.
- Push token: a Firebase Cloud Messaging (FCM) token so we can send you notifications.
- Usage & log data: technical logs such as IP address, timestamps, requests made, and approximate location derived from those requests.
3.3 Information from third parties
- Firebase (Google): confirmation that your phone number was verified.
3.4 Sensitive / special-category data
Some of what you provide is, or can be used to infer, special-category data under the GDPR (Art. 9), sensitive personal data under the DPDP Act, and sensitive personal information under the CPRA: in particular, the combination of your gender and the gender you are seeking can indicate your sexual orientation, and we process precise geolocation. We process this data only with your explicit consent, which you give when you complete onboarding, and you can withdraw it at any time (which will end your ability to be matched).
4. How we use your data, and our legal bases
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Create and secure your account; verify you’re a real adult | Phone, device IDs, DOB | Contract; legitimate interests (fraud/abuse prevention) |
| Build your AI agent persona and embeddings | Personality inputs, profile | Consent (incl. Art. 9 explicit consent for inferred orientation) |
| Run agent-to-agent conversations and decide matches | Persona, agent answers, transcripts | Consent; contract |
| Proximity matching | Precise location | Consent |
| Show matches and enable chat | Handle, photo, age, messages | Contract |
| Send notifications (matches, your agent’s questions) | FCM token | Consent; legitimate interests |
| Safety, anti-abuse, moderation, legal compliance | Most categories as needed | Legitimate interests; legal obligation |
| Improve and debug the service | Usage/log data | Legitimate interests |
Where we rely on consent, you may withdraw it at any time (§9); withdrawal does not affect processing already carried out. Under the DPDP Act, our processing is based on your consent or on legitimate uses permitted by the Act. Under US law, we process data for the business purposes described above.
5. AI agents and automated decision-making
This is core to how Ship works, so we describe it specifically:
- Persona generation. We compile your personality inputs and profile into a written “persona” describing you, and we generate a numerical embedding of it for similarity matching.
- Third-party AI processing. The persona and the resulting agent conversations are processed by our AI providers — Anthropic (which powers the conversational agent) and Voyage AI (which generates embeddings). Under our agreements with these providers, your personal data is not used to train their AI models. (See the subprocessor table in §6.)
- Agent-to-agent conversations. Your agent exchanges messages with other users’ agents. These transcripts are stored and shown to you, and to a user you match with, as part of the match.
- “Master questions.” Your agent may pause to ask you a question; your answer is added to your agent’s private notes and may be reflected in what your agent says next.
- Automated match decisions & profiling. Each agent casts an automated YES/NO decision that determines whether two people are matched. This is automated processing (profiling) that can have a significant effect on you (whether you meet someone). You have the right not to be subject to a solely automated decision with legal or similarly significant effects: you may request human review of, contest, or object to a match decision by contacting [email protected], and you may stop automated matchmaking at any time by pausing or deleting your personality profile.
AI agents can produce inaccurate, incomplete, or unexpected statements; agent output is not a verified statement of fact about you or anyone else.
6. How we share your data
We do not sell your personal data and do not “share” it for cross-context behavioural advertising. We disclose it only as follows:
- With other users: a person you match with sees your handle, profile photo, age, and the agent-to-agent conversation. Other users do not see your raw personality answers, your exact location, your phone number, or your master-question answers.
- With service providers (subprocessors) who process data on our behalf under contract:
| Provider | Role | Data processed | Where |
|---|---|---|---|
| Anthropic, PBC | Conversational AI for the agent | Persona text, agent transcripts | United States |
| Voyage AI | Text embeddings for matching | Persona text | United States |
| Google (Firebase) | Phone authentication & push notifications | Phone number, FCM token, device data | Global (Google infra) |
| DigitalOcean | Application hosting & image object storage (Spaces) | All app data; uploaded images | Singapore (sgp1) / as configured |
| Cloudflare (confirm) | Network security / TLS / CDN | Network traffic metadata | Global edge |
- For legal and safety reasons: to comply with law, enforce our Terms, prevent fraud or harm, or protect rights and safety.
- In a business transfer: in connection with a merger, acquisition, or sale of assets, subject to this policy.
7. International data transfers
We operate globally and our providers are located in multiple countries (including the United States and Singapore). Where we transfer personal data across borders — including out of the EU/UK or India — we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum) or other legally recognised transfer mechanisms. You can request details at [email protected].
8. How long we keep your data (retention)
We keep your personal data for as long as your account is active and as needed to provide the service. When you delete your account, we deactivate it immediately and stop using your data for matchmaking. We then retain your data in a deactivated state for up to 90 days to meet legal, safety, and anti-abuse obligations, after which we delete it or irreversibly anonymise it. You may request complete erasure sooner by contacting [email protected] (subject to limited exceptions where law requires us to keep certain records).
Implementation note for the team (remove before publishing): account deletion is currently a soft delete and does not yet purge agent/personality/chat data — see the checklist in
README.md. This section must reflect what the system actually does at launch.
9. Your rights and choices
Subject to your location and applicable law, you have rights to:
- Access the personal data we hold about you, and get a copy (portability/export).
- Correct inaccurate or incomplete data.
- Delete your data (“right to erasure” / “right to be forgotten”).
- Restrict or object to certain processing, including profiling and automated decisions.
- Withdraw consent at any time (e.g. for location, AI matchmaking, or sensitive-data processing).
- Complain to a data protection authority (see region sections below).
To exercise any right, email [email protected]. We will verify your identity (typically via your registered phone number) and respond within the timeframes required by law. These rights are free to exercise, except where the law permits a reasonable fee for excessive requests.
10. Security
We protect your data with technical and organisational measures, including encryption in transit (HTTPS/TLS), access controls, and storage on secured systems. Messages are stored on our systems and are not end-to-end encrypted — please do not share information you would not want us to be technically able to access. No system is perfectly secure; we cannot guarantee absolute security, and you use the service at your own risk.
11. Region-specific information
11.1 EU / UK (GDPR & UK GDPR)
The controller is Aatavata Business Private Limited. Our legal bases are in §4. You have the rights in §9 and the right to lodge a complaint with your local supervisory authority (in the UK, the ICO). If we have no EU/UK establishment, our representative is [EU_REP] / [UK_REP]. Our Data Protection Officer (if appointed) is Honey Duhar ([email protected]). We rely on explicit consent for special-category data (§3.4) and provide safeguards for automated decisions (§5).
11.2 United States / California (CCPA/CPRA)
In the past 12 months we have collected the categories of personal information described in §3, including sensitive personal information (precise geolocation and data that may reveal sexual orientation). We use sensitive PI only to provide the service and not to infer characteristics for other purposes; you may limit the use of your sensitive PI. We do not sell personal information and do not share it for cross-context behavioural advertising. California residents have the right to know, access, correct, delete, and to be free from discrimination for exercising these rights. Submit requests to [email protected]; you may use an authorised agent.
11.3 India (DPDP Act 2023)
Ship processes your personal data as a Data Fiduciary based on your consent or other legitimate uses under the Act. You have the right to access, correction, and erasure of your data, the right to grievance redressal, and the right to nominate another person to exercise your rights in the event of death or incapacity. Our Grievance Contact is Honey Duhar ([email protected]); we will respond within the timelines prescribed by the Act, and you may escalate to the Data Protection Board of India if unsatisfied. We will obtain verifiable consent and will not process the data of individuals under 18.
12. Children
Ship is for adults 18+. We do not knowingly collect data from anyone under 18 and will delete such data if discovered. Contact [email protected] if you believe a minor has used the service.
13. Third-party links and services
The app relies on the third-party providers listed in §6, each with its own privacy practices. We are not responsible for the privacy practices of third parties; review their policies directly.
14. Changes to this policy
We may update this policy. When we make material changes, we will update the “Last updated” date and notify you in-app or by another reasonable means before the changes take effect. Your continued use after the effective date constitutes acceptance, except where the law requires fresh consent.
15. Contact us
- Data controller: Aatavata Business Private Limited, D-9/165 Chitrakoot Scheme, Jaipur, Rajasthan 302021
- Privacy / data-rights requests: [email protected]
- General support: [email protected]
- India grievance contact: Honey Duhar ([email protected])
- EU/UK representative (if applicable): [EU_REP] / [UK_REP]
- Website: https://www.aatavata.tech