This policy explains how One Shot at Love handles information across our app, signed-in
browser experience, public website, and waitlist. We built the service around a text-only
profile, coarse location, explicit matching choices, and no advertising trackers.
Who is responsible
One Shot at Love (“One Shot at Love,” “we,” “us”) operates the service and is responsible
for the information described here. Questions and privacy requests can be sent to
privacy@oneshotatlove.com.
Information we collect
Account and age information. We collect your email address, an account
identifier, authentication and session information, and your date of birth. We use the
date of birth to enforce the service’s 18-and-older rule; other players do not see it.
Profile and interview information. We collect the name, pronouns,
interview answers, character sheet, and profile text you choose to provide, together with
saved Campaign progress and settings.
Matching choices and sensitive information. If you use real-person
Matchmaking, we collect your age range, local-only or local-preferred choice, broad
identity group or groups, and the broad identity groups you are open to meeting. These
answers can reveal gender identity or sexual orientation and are treated as sensitive.
They are used to enforce reciprocal matching boundaries—not to advertise to you.
Coarse location. We collect the city or area, optional region, country,
and device timezone you confirm. We do not ask for or store GPS coordinates, a street
address, or a postal code for matching. The timezone supports draw timing and quiet-hour
notifications.
Matches and conversations. We keep draw entries and outcomes, bonds,
messages and read state, meeting plans, blocks, reports, and the safety status of
messages. A meeting plan can contain the time, public place, and “how to find me” note you
choose to share with your match.
Campaign and AI content. We keep the fictional Campaign characters and
table settings you choose, your Campaign messages and dice actions, generated replies,
outcomes, and recap text. We also process interview answers and limited profile or match
context to generate sheets, prompts, and compatibility copy.
Feedback and product activity. If you submit feedback, we collect the
text, category, feature source, platform, app version, and build version. We also collect
a small allowlisted set of product events, such as whether a Campaign began or a draw was
entered. Those events do not include free-form profile text, location, private matching
answers, or conversation transcripts.
Notifications and device information. If you allow push notifications, we
store an app-device push token. We use it for match, message, and important account-access
alerts; notification payloads do not include the body of a private message or safety-case
details.
Diagnostics and security information. Hosting, authentication, push, and
error-reporting services may process IP address, request timestamps, browser or device and
operating-system details, app version, crash traces, performance measurements, and
security signals. We configure app diagnostics for reliability and do not attach private
matching answers or chat transcripts to our own product-event records.
Waitlist details. When you fill out the “Roll Initiative” form, we
collect the name, email address, and coarse
city or area you enter. We ask you not to enter an exact address.
How we use information
To create and secure accounts, verify age eligibility, and synchronize app data.
To create character sheets, run the fictional Campaign, and operate worldwide, near-first
Matchmaking under each player’s reciprocal boundaries.
To deliver messages, meeting plans, match alerts, and other requested features.
To screen for high-risk content, receive reports, enforce blocks, investigate abuse, and
protect players and the service.
To understand whether core features work, diagnose failures, control AI cost, and improve
reliability using bounded product events and diagnostics.
To operate the waitlist and send requested launch or service communications.
To comply with law and establish, exercise, or defend legal claims.
We do not sell personal information, serve third-party ads, use personal information for
cross-app advertising, or share it with data brokers.
What another player can see
A person you are matched with can see the public parts of your character sheet, your display
pronouns, age, and the coarse city or area, region, and country you entered. They can see
messages and plans you send in that bond. They cannot see your date of birth, timezone,
email address, push token, blocks or reports, or your private identity and open-to answers.
Those private answers are evaluated only to decide whether both players’ boundaries permit a
match.
AI and message moderation
AI features send the prompt and context needed for the requested result to Vercel AI
Gateway, which routes requests to the configured DeepSeek model provider. This can include
interview answers, selected profile fields, Campaign messages and settings, or a real-person
chat message submitted for safety classification. We store generated app content when it
needs to remain consistent across sessions. Our separate AI-usage ledger stores controlled
operation and cost measurements, not prompts, outputs, or transcripts.
Obvious high-risk phrases can be stopped before delivery. Other messages may be reviewed by
automated systems after delivery and may be shown to an authorized safety operator when a
report or automated flag needs review. A clear first-person under-18 admission is retained
in a restricted safety report, pauses the sender's account, and creates an audit record; it
is not delivered to the match. Automated systems can make mistakes; players can still report
or block from the app and a paused adult can appeal at
safety@oneshotatlove.com.
Service providers and disclosure
We disclose information to service providers only as needed to run the service on our
behalf. The provider and exact data depend on the feature you use:
Clerk for account authentication and email verification.
Vercel for website, API, and AI Gateway infrastructure.
Neon for application and waitlist database hosting.
Expo, Apple Push Notification service, and Firebase Cloud Messaging for
app updates and push delivery.
Sentry for crash, error, and performance diagnostics.
Resend for waitlist and service email delivery.
Google Fonts for font files requested by the public website.
We may also disclose information when required by law, to protect rights or safety, or as
part of a merger, financing, acquisition, or sale of assets, subject to appropriate
protections. Service providers are required to handle data consistently with their
agreements with us and applicable law.
Retention and deletion
Account, profile, matching, Campaign, and conversation data is generally kept while your
account is active. Deleting the account disables it immediately and schedules the app data
for permanent deletion within 30 days.
Raw allowlisted product events expire after 90 days. Raw tester feedback, AI-usage
measurements, and privacy-minimal draw outcomes expire after 180 days.
When an account is permanently deleted, authored messages and report text are deleted.
Limited redacted safety metadata—such as report category, source, status, date, and
counterparty account identifiers—may remain in an audit record when needed to prevent
abuse, protect players, comply with law, or resolve disputes.
Waitlist details are kept until the invitation program ends, plus a reasonable period
afterward, or until you ask us to remove them, whichever comes first.
Security logs and residual backup copies may remain for a limited period under provider
schedules before they are overwritten or deleted.
Your choices
In the app’s Codex, you can download a JSON copy of your app account data or delete your
account. You can update your profile, matching boundaries, and local-only or local-preferred
choice in the app; each real-person draw is optional and requires a fresh cast. You can
disable push notifications in device settings and unsubscribe from optional email.
You may also ask to access, correct, delete, or receive a copy of personal information, or
object to or restrict certain processing where local law provides that right. Email
privacy@oneshotatlove.com. We may need to
verify the request and may retain limited information where law or a legitimate safety need
permits it. You may appeal a denied privacy request by replying to our decision.
Cookies and local storage
The public marketing pages do not use advertising or audience-measurement cookies. The
signed-in browser experience uses essential authentication cookies and local storage to keep
a session and account-scoped app state. Native apps store the authentication token in the
device’s secure Keychain or Keystore and cache app state needed for the experience.
International processing
One Shot at Love is available worldwide, and we and our providers may process information in
the United States and other countries. Those countries may have different data-protection
laws from where you live. We use provider contracts and other safeguards required for the
transfer where applicable.
Children
One Shot at Love is intended for adults aged 18 and older. We do not knowingly collect app
account information from anyone under 18. If we learn that an underage person created an
account, we will disable it and take appropriate deletion and safety steps. A clear
first-person under-18 admission automatically pauses the account for human review; an
unverified third-party report does not. Contact
safety@oneshotatlove.com with a concern.
Security
We use measures designed to protect information, including encrypted network transport,
server-side authorization, secure native token storage, least-privilege operator access, and
deletion controls. No method of storage or transmission is perfectly secure, and we cannot
guarantee absolute security.
Changes to this policy
If we update this policy, we will post the revised version here and change the “last
updated” date above.