Privacy Policy
Last updated: March 1, 2026
1. Introduction
BothWant ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, store, and share information when you use our couples' intimacy quiz platform (the "Service").
Given the intimate and sensitive nature of the data you share with us, we hold ourselves to a higher standard of privacy protection. Your quiz responses are among the most private data you could entrust to any platform, and we treat that responsibility with the gravity it deserves.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Display name
- Password (stored as a salted, one-way hash — we never store your plaintext password)
- Date of birth (for age verification — you must be 18+)
2.2 Quiz Responses
When you participate in quizzes, we collect your individual responses. These responses are:
- Encrypted at rest using AES-256 encryption.
- Never visible to your partner, other users, or our team in their individual form.
- Processed server-side only to compute mutual matches — where both partners independently select the same desire.
Only mutual matches are revealed. If you select a desire and your partner does not, your selection remains completely private.
2.3 Usage Data
We automatically collect limited technical data:
- Device type and operating system
- Browser type and version
- Pages visited and features used (no quiz-response-level tracking)
- Crash reports and performance metrics
2.4 Cookies
We use strictly necessary cookies for authentication and session management. We do not use advertising cookies, tracking pixels, or third-party analytics that profile individual users.
3. How We Use Your Information
We use your information exclusively to:
- Provide and operate the Service, including computing mutual matches.
- Authenticate your identity and verify age eligibility.
- Send transactional communications (account verification, security alerts, partner invitations).
- Improve the Service through aggregated, anonymized analytics that cannot be linked to any individual.
- Enforce our Terms of Service and protect against fraud or abuse.
We will never use your quiz responses for advertising, profiling, or any purpose beyond computing matches and improving quiz quality through anonymized aggregate analysis.
4. How We Share Your Information
4.1 With Your Partner
Only mutual matches are shared with your paired partner. Your individual responses — including desires you selected that your partner did not — are never disclosed.
4.2 With Service Providers
We use a limited number of trusted third-party service providers for infrastructure (hosting, email delivery, error monitoring). These providers:
- Are contractually prohibited from using your data for their own purposes.
- Process only the minimum data necessary to perform their function.
- Do not have access to decrypted quiz responses.
4.3 Legal Requirements
We may disclose information if required by law, subpoena, court order, or governmental request. Where legally permissible, we will notify you before such disclosure. We will challenge overbroad or inappropriate requests.
4.4 We Never Sell Your Data
We do not sell, rent, or trade your personal information or quiz responses to any third party. Period.
5. Data Security
We implement industry-leading security measures, including:
- AES-256 encryption for quiz responses at rest.
- TLS 1.3 encryption for all data in transit.
- Salted bcrypt hashing for passwords.
- Role-based access controls with principle of least privilege.
- Regular third-party security audits and penetration testing.
- Automated intrusion detection and monitoring.
While no system is perfectly secure, we employ rigorous measures appropriate to the sensitivity of the data we handle.
6. Data Retention
We retain your data as follows:
- Active accounts: Data is retained for the duration of your account.
- Deleted accounts: All personal data, quiz responses, and match history are permanently deleted within 30 days of account deletion.
- Anonymized data: Aggregated, fully anonymized statistics that cannot identify any individual may be retained indefinitely for service improvement.
- Backups: Encrypted backups containing your data are purged within 90 days of account deletion.
7. Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
- Access: Request a copy of all personal data we hold about you.
- Correction: Update or correct inaccurate information.
- Deletion: Delete your account and all associated data at any time through account settings, or by contacting us.
- Export: Request a machine-readable export of your data.
- Restriction: Request that we limit processing of your data in certain circumstances.
- Objection: Object to processing of your data where we rely on legitimate interests.
To exercise any of these rights, contact us at privacy@bothwant.com. We will respond within 30 days.
8. Age Verification
The Service is strictly for users aged 18 and older. We implement age verification at account creation and reserve the right to request additional verification at any time.
If we learn that a user under 18 has created an account, we will immediately terminate the account and permanently delete all associated data. If you believe a minor is using the Service, please contact us at safety@bothwant.com.
9. International Data Transfers
Our servers are located in the United States. If you access the Service from outside the US, your data may be transferred to and processed in the US. We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses where required by applicable law.
10. California Privacy Rights (CCPA)
California residents have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect, the right to delete it, and the right to opt out of any sale. As stated above, we do not sell personal information. To exercise your CCPA rights, contact us at privacy@bothwant.com.
11. European Privacy Rights (GDPR)
If you are located in the European Economic Area, the UK, or Switzerland, you have rights under the General Data Protection Regulation including the rights described in Section 7. Our legal basis for processing your data is contractual necessity (to provide the Service) and your explicit consent for processing sensitive data (quiz responses about intimate desires).
You may withdraw consent at any time by deleting your account. You also have the right to lodge a complaint with your local supervisory authority.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email and in-app notification at least 14 days before taking effect. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
13. Contact Us
For privacy-related questions, concerns, or data requests, contact us at:
- Email: privacy@bothwant.com
- Data Protection Officer: dpo@bothwant.com