Skip to content
in·two

Privacy

Document · version of 3 October 2026

The service runs without registration, so there is very little data: no email, no phone number, no first or last name. Below is exactly what we collect, why, from whom and for how long. Questions: privacy@intwo.app

1. Who controls the data

The data controller is the in·two project. Every request about this policy, about deletion and every complaint goes to privacy@intwo.app — the same address listed in the terms of use.

2. What data we collect

  • Profile data. Nickname, age, profile type, area or region, country, the about-you text, avatar colour, status, sent-message counter and registration date.
  • Messages. The text, its kind (message, image, file), send time and read receipts.
  • Files. Uploaded images and documents: name, type, size, checksum and the file content itself.
  • Historical couple data. For accounts moved to a Couple profile type, previous partner details remain with legacy conversations and reports. New Couple profiles use the same single-account fields as other profile types.
  • Technical session data. A hash of the session token, an irreversible hash of the IP address, the user-agent string and the time of the last visit.
  • Moderation. Who blocked whom and which reports were filed (with date, reason and the text you typed).

To be explicit: no email address, no phone number, no real name, no passport data and no precise coordinates are ever collected. Country and region can be suggested from an approximate IP lookup; you can edit both before entering.

3. Why we need it

Card, message and file data is processed to perform the contract — so the chat works at all: see the list, write to someone, get an answer, upload a file. Technical session data rests on legitimate interest: throttling entry and sending keeps automated mailshots from taking the place of real people. Moderation data is legitimate interest too, plus meeting child-protection obligations. Where third-party data appears — a report describing another person — that separate basis applies.

We never process data for advertising and build no ad profiles: there are no ad networks, pixels or third-party trackers on the site at all.

When you open the entry form through our trusted proxy, we may send your IP address to ipapi.is to suggest a country and region. This does not request your device location. The lookup is approximate and can be wrong. If it fails or is unavailable, the fields stay blank for you to fill in. The provider receives the address to answer the lookup; its handling of that request is covered by its own privacy policy.

4. The IP address hash

We do not store an IP address as-is. We hash it using a server-side secret kept outside the database: the original address cannot be recovered from the hash even with full database access. The hash is used for entry limits, message throttling, related reports and a temporary lookup cache. That cache holds the hash and suggested country and region for up to two hours. The raw address is sent to ipapi.is for the optional location suggestion, but is not kept in our database or cache.

5. Who receives the data

Infrastructure providers — hosting, bot protection, email delivery — receive only what the service needs to run. ipapi.is receives an IP address when an approximate location suggestion is requested. State authorities receive data only within and in the manner directly provided by law, on an official request. There is no selling, trading or transfer to ad networks.

If the service changes operator or moves to another jurisdiction, this page says so before the change takes effect.

6. How long we keep it

  • • Browser sign-in cookie — until the browser session ends.
  • • Server-side session validity — up to 30 days after the last activity.
  • • Card, messages and files — while the account or couple card exists.
  • • Reports and blocks — up to 12 months, to see violation history and count repeats.
  • • Technical server logs — no longer than needed to diagnose incidents.
  • • Approximate location lookup cache — up to two hours in server memory.

Deleting an account removes the card, the messages and the files. Exceptions are records we must retain by law and the block entry that protects other people from contact with the same account again.

7. Your rights

At any time you can view your profile after entry, change age, profile type, location and the about-you text in Profile settings, hide the profile, or delete the account entirely. Requests for a data export, correction or deletion go to privacy@intwo.app; we answer within 30 days.

You may withdraw consent, demand restriction of processing and complain about the controller. In Russia that goes to Roskomnadzor, in the EU to your local data-protection supervisory authority. Users elsewhere hold the same rights within applicable law.

8. Cookie

One technical cookie runs the site: the session identifier. It keeps you signed in across reloads until the browser session ends, is unreadable from page scripts and is never used for advertising. No analytics, advertising or social pixels are loaded.

9. Children

The service is adults-only and we never knowingly collect children’s data. When an account created by a minor is found — through a report or obvious signs — it is deleted and that report is reviewed first; details are in the rules. A deletion request for such data goes to privacy@intwo.app and we remove it without extra questions.

10. Changes

This policy is updated on this page. When a change affects how data is processed or retained, the new version applies from its publication date and existing accounts move onto it at next entry. Questions on any clause: privacy@intwo.app.