Privacy Policy
Effective date: April 27, 2026 Last updated: July 26, 2026
1. Who We Are
Tenikopr operates DancingPartners, a dating and social-discovery mobile application for adults who love to dance — any style, any level (“App”). When we say “we,” “us,” or “our,” we mean Tenikopr.
- Operator: Tenikopr
- Contact: developers@tenikopr.com
- Country of operation: Puerto Rico, United States
This Privacy Policy describes how we collect, use, share, and protect your personal information when you use our App and website at dancingpartners.app.
2. Where This Privacy Policy Applies
This Privacy Policy applies to the DancingPartners mobile application (iOS and Android) and our website at dancingpartners.app. It does not apply to third-party services you may access through links in the App or website — those services have their own privacy policies and we encourage you to read them.
3. Data We Collect
We collect information in three ways: information you give us directly, information we collect automatically, and information from third-party services when you choose to connect them.
Information you give us
- Account credentials: you sign in with Google, Apple, or your email address via Supabase Auth. Email sign-in is passwordless — we send a one-time code rather than asking you to choose a password — so we do not collect or store a password for your account. When you sign in with Google or Apple we receive your name and email address from them and use that email as your account email.
- Phone number: after signing in, every account must verify a phone number. We send a one-time SMS code to the number you enter (via Google’s Firebase Phone Authentication) and, once it is confirmed, we store that phone number on your account along with the date it was verified and a one-way hashed copy used to stop the same number being used for multiple active accounts. The phone number is not used as your login and is never shown to other users.
- Email verification: if you sign in with Apple using its private relay address, we also ask you to confirm a working email address, which we store on your account.
- Profile information: your name, date of birth, gender, bio, dance styles, skill level, and your match/search preferences (age range, distance, gender preference, and preferred dance style).
- Photos: profile photo and any additional photos you upload to your album. Each uploaded photo must clearly show a human face (checked on your device) and is automatically screened for unsafe content before it goes live (see “Photo moderation” below).
- Face scan (verification selfie): a selfie captured during the face-verification flow, which every account must complete before using the App. Your device uses Google ML Kit to find your face and guide the on-screen liveness prompts, but the captured image itself is transmitted to our servers and to Amazon Web Services for age estimation and for comparison against your profile photos. We ask for your explicit consent before the camera is turned on. See “Biometric data: face verification” below.
- Communications: chat messages you send to matches, and reports or feedback you submit to us. Chat messages are transmitted over encrypted connections (HTTPS/TLS) and stored on our servers, where they may be processed by automated systems and, where necessary, reviewed by our team for safety, moderation, support, and legal compliance — see “Chat messages and moderation” below.
Information collected automatically
- Location: precise GPS coordinates when the App is open and in the foreground. We use this to show you potential dance partners nearby via our proximity-matching feature. We do not track your location in the background.
- Device information: device model, operating system version, language setting, a per-install device identifier (a random opaque token we generate and store on your device and account — not your advertising ID and not a hardware fingerprint — used solely to enforce device-level bans for repeated safety violations), and an advertising identifier (the Google Advertising ID on Android, provided by Google Play Services, or Apple’s Identifier for Advertisers (IDFA) on iOS). On iOS we ask your permission through Apple’s App Tracking Transparency prompt before using the IDFA for personalized ads; you can decline and still use the App with non-personalized ads.
- IP address: your device’s IP address, used for security, rate-limiting (for example, throttling verification-code requests), and fraud/abuse prevention. We do not use it to track you across other apps or websites.
- Usage data: which profiles you view, swipes (likes and passes), matches created, and general in-app interactions.
- Push notification token: a Firebase Cloud Messaging (FCM) registration token used to deliver notifications about new matches, messages, likes, dance ratings, re-engagement reminders, conversation nudges, occasional promotional offers, and app updates — all controllable in Settings → Notifications. For chat-message notifications we only include a generic “Nuevo mensaje” body and the match ID — never the actual message text, as a privacy measure.
- Crash and diagnostic data: stack traces, device state at the time of a crash, and anonymized installation identifiers, collected via Firebase Crashlytics to help us fix bugs.
- Platform age signals: during onboarding, before the registration form, the App queries your device’s age-assurance APIs — Apple Declared Age Range (iOS 17.4+) and Google Play Age Signals (Android) — which return an age range or age-range signal used to help block minors from registering. This is in addition to the Amazon Rekognition age estimate described under “Biometric data: face verification” below.
Biometric data: face verification
Face verification is required to use DancingPartners. Before we turn on your camera, we show you a consent screen describing what we collect and ask you to affirmatively agree; the camera does not open until you do.
What we collect. A face scan — a live selfie taken with your front camera at the end of a short liveness sequence (you are asked to do things like blink, smile, or turn your head). The live selfie is a single still photo; we do not record audio or video.
Why we collect it. To confirm you are a real person and not a bot, to estimate that you meet our 18+ minimum age, and to check that the person in the selfie is the same person shown in your profile photos.
How it is processed — partly on your device, partly on our servers.
- On your device: Google ML Kit Face Detection tracks your face in the camera preview and drives the liveness prompts. During the liveness sequence the App also reads on-device motion sensors (accelerometer/gyroscope) to detect spoofing, such as a device held perfectly still on a tripod; this sensor data is processed on your device and is not stored or transmitted. This step runs locally.
- On our servers and at Amazon Web Services: the captured selfie is then sent from your device to our backend (Supabase Edge Functions) and from there to Amazon Rekognition, a third-party biometric service operated by Amazon Web Services, Inc. Rekognition is used twice: once to estimate your age range, and once to compare your face scan against your profile photos. This is a real transmission of your image off your device — it is not an on-device-only check.
How the results are used. If the estimated age is below 18, registration is rejected and an internal review record is created. If your face scan does not match any of your profile photos, the verification does not pass and your account is not marked as identity-verified. If the checks cannot run at all for technical reasons (for example an outage at our provider), they are designed to fail open — you are let through rather than locked out, and the account may be marked verified without a completed check. The verified status is therefore not a guarantee; see Section 10 of our Terms of Service.
Limits on use. Your face scan is never shown to other users, never added to your profile or photo album, and never used for advertising or ad targeting. We do not sell it.
Retention. Your face scan is processed transiently to complete this verification. We do not save the image to our storage or database, and we do not enroll it into any searchable face database or biometric index — Amazon Rekognition is called statelessly, image by image, and no face template or faceprint is created or kept on our side. What we keep afterwards is the outcome (whether your account is identity-verified), not the image. Amazon Web Services processes the image as our service provider and handles it under its own terms and retention practices, which we do not control; see the AWS privacy notice linked in Section 5.
Your choice. Because verification is required, declining consent means you cannot complete sign-up or continue using the App — the only alternative offered on the consent screen is to cancel and sign out. You can delete your account at any time (see Section 9).
Chat messages and moderation
Chat messages you send through DancingPartners are not end-to-end encrypted. They are:
- Transmitted to our servers over encrypted connections (HTTPS/TLS).
- Stored in our database (hosted by Supabase) and included in our encrypted database backups.
- Accessible to our systems and, where necessary, to authorized Tenikopr staff — to deliver your messages, run content moderation and keep the community safe, respond to your reports and support requests, and comply with valid legal process.
What this means for your privacy:
- Because we can access message content, we are able to investigate reports, enforce our Community Guidelines, and — when legally required — produce message content in response to valid legal process.
- We do not sell your messages and we do not use their content for advertising.
- Push notifications still do not include message content. For your privacy, chat notifications contain only a generic “Nuevo mensaje” body and the match ID.
Content moderation
To help keep the community safe, DancingPartners checks chat messages for offensive or harmful content in two complementary ways:
- Before sending: when you finish typing a message, the text is sent to our servers and on to OpenAI’s automated moderation service for a toxicity check, before the message goes to the recipient. If it is likely offensive, hostile, threatening, or otherwise inappropriate, the App shows a warning asking you to confirm or edit the message. This check does not run on your device. If the check cannot be completed quickly it fails open and your message is sent unchecked.
- On our servers, after delivery: when a message is stored on our servers, automated systems scan its content against a curated list of prohibited keywords, phrases, and patterns maintained by our moderation team. Messages that match are flagged for review by authorized Tenikopr staff. This server-side check does not block or delay message delivery — your message is always delivered, but may be reviewed afterward. Flagged messages are logged with a short excerpt of the content and the category of violation detected (e.g., harassment, hate speech, spam). If a user accumulates multiple flagged messages, our systems may automatically generate an internal report for staff review and, in cases of severe or repeated violations, may result in an automatic device-level ban (see our Terms of Service, Section 9). We may also use human review to investigate reports submitted by other users or to follow up on automated flags.
Photo moderation
Before a photo you upload is published to your profile, two checks run:
- On your device, before upload: Google ML Kit Face Detection confirms the photo contains a clearly visible human face. Photos with no recognizable face are rejected before they are uploaded — this check runs locally and the image is not sent anywhere for it.
- On our servers, before publishing: the uploaded image is screened for sexual, violent, or otherwise unsafe content by OpenAI’s automated moderation service. We generate a short-lived signed link to the image and send it to OpenAI solely for this automated safety check; per OpenAI’s API terms, content sent to its moderation endpoint is not used to train its models and is not retained for that purpose. Photos that fail are deleted and never published, and repeated violations may trigger an internal report and, in severe or repeated cases, a device-level ban (see our Terms of Service). If this safety check cannot be completed (for example, a provider outage), the photo is not published — the check fails closed.
Information we do not collect
- Message previews in push notifications (we send only a generic “Nuevo mensaje” body)
- Background location
- Audio or voice recordings — the App never records, stores, or transmits any sound. A microphone permission appears on iOS only because the camera component used for the live-selfie identity check links the system audio APIs; audio capture is disabled (enableAudio: false) and no sound is ever captured
- Your contacts, call logs, or the content of your SMS messages (we send you a one-time verification code, but we cannot read your messages — see “Phone number” above for the number we do store)
- Browsing history outside the App
- Fingerprints, iris scans, or the biometrics your phone uses to unlock itself (Face ID / Touch ID data never leaves your device and is never shared with us)
- Stored face templates or faceprints — we do collect a face scan for verification, but it is not enrolled into a searchable biometric database or kept as a template (see “Biometric data: face verification” above)
4. Why and How We Use Your Data
We use the information we collect for the following purposes:
| Purpose | Legal basis |
|---|---|
| Create and manage your account | Contract performance |
| Verify that you are a real person, estimate that you are 18 or older, and confirm your face scan matches your profile photos | Consent (biometric data); Legal obligation (age restriction) |
| Obtain platform age signals (Apple Declared Age Range / Google Play Age Signals) to help block minors | Legal obligation (age restriction) |
| Show you potential matches based on location and preferences | Contract performance / Legitimate interest |
| Enable chat between matches | Contract performance |
| Send push notifications about matches, messages, likes, ratings, re-engagement reminders, and occasional promotional offers | Contract performance (service notices) / Consent; Legitimate interest (re-engagement and promotional — opt out in Settings) |
| Display advertisements via Google AdMob | Legitimate interest (non-personalized); Consent (personalized, where required) |
| Detect fraud, enforce our Terms of Service and Community Guidelines, including automated content moderation of chat messages | Legitimate interest |
| Fix bugs and improve app performance via crash analytics | Legitimate interest |
| Comply with legal obligations | Legal obligation |
Automated decisions
Two of our automated systems can make decisions that significantly affect you without a person reviewing them first:
- Automated age estimation. During face verification, Amazon Rekognition estimates an age range from your face scan. If the midpoint of that range falls below 18, registration is automatically blocked on the spot. This is a statistical estimate produced by software — it is not proof of age, and it can be wrong, particularly for adults whose appearance reads as younger. Blocked attempts are recorded in an internal queue for our staff to review afterwards.
- Automatic device ban. If an account repeatedly uploads photos that fail our safety screening, or accumulates repeated chat messages flagged by our server-side moderation, our systems can ban the device automatically once a violation threshold is reached, without prior human review (see “Content moderation” and “Photo moderation” in Section 3 and Section 9 of our Terms of Service).
If you believe an automated decision about you was wrong, email us at developers@tenikopr.com and a person will look at it — see Section 12 for contact details and response times.
Other than the decisions described above, we do not use your data to make automated decisions that significantly affect you without human review.
5. How We Share Data
We do not sell your personal information. We do not share your data with third parties for their own marketing purposes. We share data only as follows:
With other users: your profile information (name, photos, dance styles, skill level, bio, approximate distance) is shown to other users as part of the matching experience. Your precise location coordinates are never shown to other users — only a calculated distance.
With service providers: we work with the following sub-processors who handle your data on our behalf:
| Sub-processor | Purpose | Data involved | Privacy policy |
|---|---|---|---|
| Supabase, Inc. | Cloud database, object storage, and authentication backend (identity management for social sign-in) | Account data, profile photos, swipes, location, and chat messages (stored as content; see “Chat messages and moderation” in Section 3) | supabase.com/privacy |
| Google LLC — Sign-In with Google | Social authentication identity provider | Email address, display name, profile picture | policies.google.com/privacy |
| Apple Inc. — Sign-In with Apple | Social authentication identity provider | Email address (or Apple relay address), display name | apple.com/legal/privacy |
| Google LLC — Firebase Phone Authentication | Sending the one-time SMS code that verifies your phone number | Phone number, SMS delivery metadata | policies.google.com/privacy |
| Google LLC — Firebase Cloud Messaging | Push notifications | FCM token, notification payload | policies.google.com/privacy |
| Google LLC — Firebase Crashlytics | Crash reporting and diagnostics | Crash logs, device model, OS version, anonymized install ID | policies.google.com/privacy |
| Google LLC — Firebase App Check | Device-integrity attestation (Google Play Integrity on Android, Apple App Attest on iOS) used to block bots and abuse on sensitive actions such as photo and face-verification checks | Device-integrity token; no additional personal data | policies.google.com/privacy |
| Google LLC — Google AdMob | In-app advertising | Advertising ID, ad interaction events; consent status in applicable regions | policies.google.com/technologies/ads |
| Amazon Web Services, Inc. — Amazon Rekognition | Biometric face verification: age-range estimation and comparison of your face scan against your profile photos | Your face scan (verification selfie) and your profile photos | aws.amazon.com/privacy |
| Resend, Inc. | Transactional email — email-verification codes (for Apple private-relay sign-ins), account-recovery codes, and account-deletion confirmations | Email address, email content | resend.com/privacy |
| OpenAI, L.L.C. | Automated safety moderation of uploaded photos and chat messages | Message text; a short-lived signed link to an uploaded photo (not retained for training) | openai.com/policies/privacy-policy |
For legal reasons: we may disclose your data if required by law, subpoena, or other legal process, or if we have a good-faith belief that disclosure is necessary to protect our rights, your safety, or the safety of others.
Business transfers: if Tenikopr is acquired or merges with another entity, your data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
6. How Tenikopr Works
DancingPartners is operated solely by Tenikopr, a company based in Puerto Rico, USA. We do not belong to a group of related companies that shares your data for joint marketing or cross-service matching purposes. Any future changes to our corporate structure that affect how your data is used will be communicated to you with advance notice.
7. Cross-Border Data Transfers
Our backend infrastructure is hosted in the United States through Supabase (on AWS us-east-1). If you access DancingPartners from outside the United States, your personal information is transferred to and processed in the United States. By using the App, you acknowledge this transfer.
This includes your face scan, which is sent to Amazon Rekognition in a United States AWS region for the verification described in Section 3.
We rely on Supabase’s, Google’s, and Amazon Web Services’ data processing agreements, which include appropriate safeguards, to protect your data during any international transfers.
8. Your Rights
Depending on where you live, you may have the following rights with respect to your personal data:
- Access: request a copy of the personal data we hold about you.
- Correction: update inaccurate information (most profile fields are editable directly in the App under Profile → Edit).
- Deletion: delete your account and data (see Section 9 and our Account Deletion page at dancingpartners.app/delete-account).
- Objection: object to processing based on legitimate interests.
- Restriction: ask us to restrict certain processing while a dispute is resolved.
- Portability: request your data in a structured, machine-readable format.
- Withdraw consent: where processing is based on consent (e.g., personalized advertising), you may withdraw it at any time without affecting the lawfulness of prior processing.
- Complaint: lodge a complaint with your local data protection authority.
To exercise any of these rights, email us at developers@tenikopr.com with the subject “Privacy Request.” We will respond within 30 days (or the period required by applicable law). We may ask you to verify your identity before fulfilling the request.
California residents: see our California Privacy Supplement at dancingpartners.app/california for rights under the CCPA/CPRA.
9. How Long We Retain Your Data
- Active account data: retained for as long as your account is active.
- Phone number: stored on your account for as long as the account is active. It is cleared from your account if the same number is later verified by a different account, and is deleted with the rest of your data when you delete your account.
- Face scan (verification selfie): processed transiently to complete the verification and not retained by us — we do not write it to our storage or database and we do not keep a face template. We retain only the result of the check (whether your account is identity-verified) for as long as your account is active. Amazon Web Services handles the image it receives under its own retention practices.
- Chat messages: retained while the conversation exists. Permanently deleted when you delete your account or unmatch. Encrypted database backups containing them are destroyed within 30 days on the rotation schedule below.
- Deleted account data: when you delete your account, your profile, photos, swipes, matches, and messages are permanently deleted. Encrypted database backups containing your data are destroyed within 30 days of deletion on their normal rotation schedule.
- Content moderation logs: records of messages flagged by our automated moderation systems are retained for up to 90 days after the flag is reviewed and resolved, or until the associated account is deleted, whichever comes first.
- Administrative audit logs (account creation, deletion events, moderation actions): retained up to 90 days for fraud prevention and dispute resolution.
- Crashlytics data: retained 90 days per Google’s standard retention policy.
- AdMob interaction data: retained per Google’s advertising data retention policies.
- Anonymized and aggregated analytics: retained indefinitely (cannot be linked back to you).
10. Children’s Privacy
DancingPartners is intended for adults who are 18 years of age or older. We do not knowingly collect, use, or share personal information from anyone under 18.
If you believe that a minor has created an account or provided us with personal information, please contact us immediately at developers@tenikopr.com with the subject “Minor account report.” We will investigate and, if confirmed, delete the account and associated data promptly.
We do not operate any section of our App or website directed at children, and we do not knowingly allow anyone under 18 to register.
11. Privacy Policy Changes
We may update this Privacy Policy from time to time as our practices change or as required by law. When we make material changes, we will:
- Post the updated policy with a new “Last updated” date at the top of this page.
- Notify you via push notification or email at least 30 days before the changes take effect.
Your continued use of the App after the effective date of the updated policy constitutes your acceptance of the changes. If you do not agree with the updated policy, you may delete your account before the changes take effect.
12. How To Contact Us
For questions, requests, or complaints related to this Privacy Policy or how we handle your personal data:
Email: developers@tenikopr.com Subject line: “Privacy” or “Privacy Request” Operator: Tenikopr — Puerto Rico, USA
We will respond to all inquiries within 30 days.
© 2026 Tenikopr. All rights reserved.