Privacy
Last updated 4 August 2026
DateCard is a dating profile you publish as a web page and hand to people. This explains, in plain language, what that means for your information.
Read this part first
Your card is public. That is the entire point of it.
Everything you put on a DateCard — your photos, your name, your answers, the ways to reach you — is published on a web page at its own address so you can give that address to someone. Anyone who has the link can open it, and anyone who has the link can forward it. Nothing on a card is private. Put nothing on it you would not hand to a stranger on paper.
The short version
- No account, no signup, no password, no email address required.
- Everything on your card is published publicly at your link, by design.
- Your card is unlisted and not indexed by search engines — but a link can always be forwarded.
- No tracking, no analytics, no advertising, no crash-reporting SDKs, no data selling or sharing.
- You can delete your card, and every photo on it, in one tap. It is immediate and permanent.
- DateCard is for adults, 18 and over.
There is no account
DateCard has no accounts. There is no signup form, no password, no username, and no email address to hand over. You build a card in the iOS app (or in your browser at date-card.app/new), press Publish, and get a link back.
Because there is no account, we have no identity for you on file. We cannot look you up, we cannot email you, and we cannot tell whether two cards belong to the same person. The only exception is Sign in with Apple, which is optional and described below.
What is on your card, and what we store
We store exactly what you type and upload, and nothing else:
- The words. Your name, tagline, age, location, hometown, height, weight, job title, company, school, education, gender, pronouns, sexuality, who you are interested in, what you are looking for, religion, politics, drinking, smoking, cannabis, kids, exercise, pets, languages, zodiac, your prompt answers, your fun facts, and your interests.
- Your photos. Up to ten, in the order you set.
- The ways to be contacted that you chose to add. Instagram, X, TikTok or Snapchat handles, a phone number, an email address, or your own website — only the ones you add. These are published as tappable links on your card.
Your name is the only required field. Every other field is optional, and leaving one blank means it is not stored and does not appear anywhere — there is no hidden record of a field you skipped.
Location is text you type, like “Charlotte, NC”. The app never asks for your device location. There is no GPS, no location permission, and no map.
Photos are served from their own addresses under /photos/ with long random identifiers. Those addresses are public too, and a photo address works on its own — someone who has it does not need your card link.
Sensitive fields: sexuality, religion, politics
A dating profile asks some questions that privacy law — and Apple — treat as sensitive personal information. DateCard has optional fields for sexual orientation, religious beliefs, and political views.
- They are entirely optional. Every one of them offers “Prefer not to say.”
- Leaving one blank means it is omitted completely — not stored, not displayed, not inferred from anything else.
- If you do fill one in, it is published publicly on your card, exactly like every other field, readable by anyone who opens your link.
Only fill these in if you want them read by whoever you share the card with. You can clear them at any time by editing your card, and the change is live immediately.
The same applies to a phone number or email address you add as a contact method: adding one publishes it.
Unlisted, not secret
Your card is unlisted. It is served with a noindex directive, which tells search engines not to index it. There is no directory, no feed, no browse, no search, no “people nearby”, and no way — in the app or on the web — to discover somebody else’s card. The only route to your card is the link.
The link is deliberately hard to guess: your first name plus a twelve-character random suffix. Nobody is going to stumble onto it by typing names into the address bar.
But the link is the only thing protecting the card. Anyone you send it to can forward it, screenshot it, or post it somewhere public — and if they post it somewhere public, that is out of our hands. Share your link the way you would hand someone a printed photo of yourself.
Where the data lives
DateCard runs entirely on Cloudflare. Your profile text is stored in a Cloudflare D1 database; your photos are stored as files in Cloudflare Workers KV. Cloudflare hosts and processes this data on our behalf as our infrastructure provider.
Your card is not copied anywhere else. There is no mailing list, no CRM, no analytics warehouse, no backup service, and no other company with a copy.
Like any web host, Cloudflare handles the network requests that reach the site and keeps standard operational logs (things like IP addresses and requested paths) for security and abuse prevention. We do not build profiles from that, and there is no analytics layer on top of it.
If you use the web editor
While you are building a card at /new, the draft and the photos you have picked stay in your own browser (local storage and IndexedDB) on that device. Nothing is sent to the server until you press Publish.
Your edit key
When you publish, the server generates one random edit key and gives it to you once. Server-side we keep only a SHA-256 hash of it — enough to check a key that is presented to us, not enough to reproduce the key itself. Nothing else authorizes changes to your card.
On iOS the key is stored in the device Keychain. In the web editor it is stored in that browser’s local storage. Every change — editing text, adding or removing photos, taking the card offline — requires it.
Two things worth being blunt about:
- Anyone who has your key can edit or delete your card. It is not a password you share.
- If you lose it, we cannot give you another one. New phone with no backup, deleted app, cleared browser — the key is gone, and we do not have it. You would no longer be able to edit or take down that card.
If that happens and you need a card removed, email hello@date-card.app. We will ask you to show that the card is yours — for example, by replying from the email address on it or messaging from the account it links to — and then take it down.
Sign in with Apple is optional
Sign in with Apple exists in DateCard for exactly one purpose: getting your own card back on a new device. It is never required, and there is nothing behind a login.
When you tap “Back up with Apple”, Apple sends us a signed token. We verify it and store only the opaque identifier Apple assigns you for this app, next to the id of your card. We never receive or store your name or your email address — the app does not ask Apple for them. That identifier is meaningless outside DateCard and cannot be used to contact you.
Restoring on a new device rotates the edit key: a new key is issued to the device doing the restore and the old key stops working. That is deliberate — it is what makes “I lost my phone” safe.
You can unlink at any time, and deleting your card deletes the identity link with it. If you never use Sign in with Apple, we hold no identifier for you at all.
What we do not do
- No tracking. No analytics SDK, no crash-reporting SDK, no tracking pixels, no advertising identifiers, no fingerprinting. Nothing measures your behaviour in the app or on the site.
- No advertising. DateCard shows no ads and runs no ad network.
- No selling or sharing. Your information is never sold, rented, traded, or shared with data brokers, advertisers, or anybody else for marketing. There is no “partner” to share it with.
- No cookies. The site sets none.
- No third-party SDKs in the app. The iOS app has no external dependencies.
One honest footnote
These pages and published cards load two typefaces (Fraunces and Inter) from Google Fonts, so your browser fetches those files from Google’s servers, which means Google sees the request. It is a font download, not a tracker — but it is a request to a third party, so we would rather say so than quietly not mention it.
Deleting your card
“Take my card offline” — in the app’s Share tab, or at the bottom of the web editor — deletes the card. That means the profile record, every photo attached to it, and any Apple identity link are removed from our storage, and the link stops resolving: it returns a “card not found” page from that moment on.
It is immediate and permanent. There is no trash, no thirty-day grace period, no archived copy, and no way for us to restore it. If you want your card back, you publish a new one and get a new link.
What deletion cannot do: reach copies that already left. If somebody screenshotted your card, saved a photo, or forwarded the link to a group chat, deleting the card does not recall any of that — the same as with anything else published on the internet. Search engine caches and link previews in messaging apps can also linger for a while after the page is gone. We can delete what we hold; we cannot delete what someone else already has.
You have to be 18
DateCard is a dating profile and is for adults only. You must be 18 or older to publish a card. The age field does not accept a number under 18, and the app is rated for adults on the App Store.
Children’s data
DateCard is not directed to children and is not designed or marketed for anyone under 18. We do not knowingly allow a minor to publish a card and we do not knowingly collect information from anyone under 18.
If you believe a card belongs to a minor, please report it or email hello@date-card.app. We treat this as urgent, and cards involving a minor are taken down. If you are a parent or guardian and your child has published a card, email us and we will remove it.
Reporting a card
If a card is abusive, sexual, harassing, impersonating someone, involves a minor, or is otherwise illegal, tell us: date-card.app/report, or email hello@date-card.app. A person reads every report, and cards that break these rules are taken down.
Your choices, in practice
Because there is no account, the controls are direct ones. To see what we hold about you, open your card — it is all of it, plus the hash of your edit key. To correct or remove something, edit your card; changes go live immediately. To delete everything, take your card offline.
If you are somewhere with statutory data rights (the UK, the EU, California, and others) and want to exercise them another way, email hello@date-card.app and a person will handle it.
Changes to this policy
If this policy changes, the updated version is posted on this page and the date at the top changes with it. Anything significant gets called out plainly rather than buried. Since we have no email address for you, this page is the only place changes are announced — worth a look if you keep a card published for a long time.
Contact
Privacy questions, deletion help, or anything else about how DateCard handles your information:
A person reads this address. Expect a reply within a couple of days.