Effective date: September 2, 2026
Last updated: August 28, 2026
1. Introduction
This Privacy Policy describes how Novi Connections Inc. ("Novi," "we," "us," or "our") collects, uses, retains, and discloses information in connection with the Novi mobile application and the novidate.com website (together, the "Services"). The Services are currently available only in the Atlanta, Georgia metropolitan area.
Biometric information is addressed in the Novi Biometric Information Policy, which supplements this Privacy Policy and is available at novidate.com/biometric-policy.
If you have questions about this Privacy Policy, contact us at support@novidate.com.
2. Information We Collect
2.1 Information you provide
Account information. Your phone number (which serves as your account identifier and is used to send sign-in codes), first name, date of birth, and an optional recovery email address. Your date of birth cannot be changed after account creation.
Profile information. Your gender; the gender or genders you wish to meet; your preferred age range; your faith and its visibility setting; your ethnicity, if you choose to share it, and its visibility setting; lifestyle responses (drinking, smoking, and family plans); education; career; local favorite places; written responses to profile prompts ("Sparks"); three profile photographs; and your standing weekly availability for scheduled calls.
Certain profile fields offer a visibility setting. Hiding a field removes it from your visible profile; the underlying answer is still used for matching. Ethnicity is used in matching only where a member has chosen to meet people who share their own; it is never used to rank or score members, and never for measurement or analytics.
Verification information. A brief video selfie and related facial data, processed to confirm that you are a real, live person and that your profile photographs are of you. This processing involves biometric information and is described in the Novi Biometric Information Policy. We request your express consent before this processing occurs, and verification cannot proceed without it.
Location information. We collect approximate location information only. During sign-up you may either enter your city or allow a one-time device location check; if you use the device location check, coordinates are reduced to approximately one-kilometer precision before use. We do not collect precise GPS coordinates and do not track your location on an ongoing basis. Other members see only a distance or neighborhood label, never your location.
Communications. Messages you exchange with matches through the in-app chat; reports you submit; and correspondence you send to us.
Date check-in responses. About a week after a scheduled call opens a chat, we ask you once whether you and the other member met up in person. Answering is optional, and you are asked only about your own experience. Your answer describes something that happened outside the Services. It is visible only to the Novi team: it is not shown to the other member, and your answer never changes what the other member sees or receives. It is not used to rank members or to decide who is introduced to whom. We use it to understand how often introductions lead to people meeting in person, and it may affect when the application asks you to rate it.
Waitlist information. If you sign up for the waitlist outside our service area: your approximate location or city; your email address (required when you sign up on our website, where email is the only way we can reach you; optional in the app, where a device notification token can serve instead); and, if you signed up in the app, that device notification token. This information is used to notify you when the Services open in your area, and occasionally about the launch itself.
2.2 Information generated through your use of the Services
- Verification results and numeric scores (no facial imagery is included in these records);
- Records of matches, scheduled calls, and related activity;
- Calendar free/busy windows, if you choose to connect a calendar. Only your free/busy windows are ever used. Never your event details.
- Device notification tokens and a log of notifications sent to you;
- Usage information, such as the screens you visit in the application, the sign-up steps you complete, taps on application controls, and similar interaction events. These records describe your use of the application's features; they do not include the content of your messages or profiles you view. See Sections 4 and 5.1 for how this information is used;
- Technical logs and crash reports generated when the application encounters an error, used to keep the application working correctly;
- Moderation, safety, and enforcement records, including reports and blocks.
2.3 Information we do not collect
We do not purchase information from data brokers, collect information from social media platforms, use advertising identifiers, access your contact list, or collect precise GPS location. We do not conduct criminal background checks or identity verification beyond the verification described above; see the Terms of Service for related disclaimers.
2.4 Payment information
When paid features launch, purchases will be processed by Apple, Google, or our payment processor. We will receive records of your purchases (the item, date, and status) but will not receive or store full payment card numbers.
2.5 Invite links
Novi may offer you a personal invite link to share with people you know. The link contains a short code that identifies the member who shared it. It contains no information about the person receiving it.
If you open an invite link, we record the code, the date and time the link was opened, and whether the request appeared to come from an automated link preview rather than from a person. We do not record your IP address, your device or browser information, or any other identifier, so this record does not identify you. The link then sends you to Novi's App Store listing. Opening an invite link does not create an account, and if you go on to join Novi, we have no way to connect your account to the link you opened.
The member who shared the link is never told whether you opened it or whether you joined. We use these records only to understand how often shared links are opened.
3. Biometric Information
The Novi Biometric Information Policy governs our collection, use, retention, and destruction of biometric information. In summary: the video selfie used for liveness verification is never stored; a single still reference image from a passed verification is retained for no more than 30 days; verification records retained beyond that period contain numeric results only, with no facial imagery; and if an account is permanently banned for serious misconduct, a facial template may be retained to prevent the banned individual from creating a new account. Photographs uploaded to any profile are screened against those retained templates; no facial geometry is retained from that screening. That retention exception, and all other biometric practices, are described in full in the Biometric Information Policy.
4. How We Use Information
We use the information described above to:
- Provide and operate the Services, including creating your profile, introducing you to other members, scheduling calls, and enabling chat;
- Decide which members to introduce you to. After each call, you and the other member are each asked privately whether you would like to keep talking. Those answers influence which members you are introduced to later, and which members you are shown to. Individual answers are never shown to the other member and are never displayed anywhere in the Services. The date check-in described in Section 2.1 is not used for this purpose;
- Verify that members are real, are of age, and match their profile photographs;
- Maintain the safety and integrity of the Services, including reviewing reports, enforcing our terms, and preventing banned individuals from returning;
- Send notifications you have enabled and service communications;
- Comply with legal obligations; and
- Understand and improve how the Services are used, through analysis of usage patterns in our own systems and through the analytics providers listed in Section 5.1.
We do not sell personal information and have never sold it. We do not use personal information for third-party advertising, and we do not serve advertising in the Services.
5. How We Share Information
5.1 Service providers
We share information with service providers that process it on our behalf and only as needed to perform their functions:
| Provider | Function | Information handled |
|---|---|---|
| Supabase | Database, authentication, file storage | Account and profile information, photographs, messages |
| Amazon Web Services (AWS) | Identity verification, photo screening, secure storage | Verification selfie stream, verification images, profile photographs (see Biometric Information Policy) |
| SMS delivery provider | Sign-in codes | Phone number |
| Expo | Push notification delivery | Notification tokens and notification content |
| Daily | Video call infrastructure | Live call audio and video (calls are not recorded) |
| Calendar free/busy access, where you connect it | Free/busy windows | |
| OpenAI | Automated screening of profile text | Text fields of your profile |
| Apple, Google, or payment processor | Payment processing (when launched) | Purchase records |
| Vercel | Hosting for the novidate.com website | Web requests to the site, including waitlist form submissions in transit |
| PostHog (hosted in the European Union) | Usage analytics | Usage events (screens visited, features used) under a pseudonymous identifier. PostHog does not receive your name, phone number, photographs, messages, location, or IP address, and cannot link the identifier back to you |
| Sentry (hosted in the European Union) | Crash and error reporting | Technical reports about application errors (device model, operating system version, and the application's state when the error occurred), scrubbed of message content and carrying at most the same pseudonymous identifier |
If you connect a Google calendar, Novi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Novi accesses only your calendar's free/busy windows and events Novi itself creates, and uses that information solely to schedule your calls.
5.2 Legal requirements and safety
We may disclose information where required by law, such as in response to a valid subpoena or court order, or where necessary to investigate or address serious safety incidents. Where legally permitted, we will notify you before disclosing your information in response to legal process.
5.3 Corporate transactions
If Novi is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. This Privacy Policy would continue to apply to your information, and we would notify you of any transaction that changes how your information is handled.
5.4 No other sharing
We do not share personal information with advertisers, data brokers, or unrelated third parties.
5.5 Third-party links
The Services may contain links to third-party websites. For example, the in-app chat may offer a shortcut to OpenTable's website for finding a restaurant. Opening such a link sends no information about you or your conversation to the third party, and Novi does not receive information about what you do on the third-party site. Novi keeps a record of which members open these links and when, to understand how the feature is used; if you delete your account, that record is anonymized so it no longer identifies you. Information you provide to a third-party website is governed by that website's privacy policy, not this one.
6. Data Retention
We retain information no longer than needed for the purposes for which it was collected, subject to the specific periods below.
| Information | Retention period |
|---|---|
| Liveness selfie video | Not stored |
| Verification reference image | Deleted automatically within 30 days of the verification check; deleted immediately upon account deletion |
| Verification results and scores | Life of the account (numeric records only) |
| Profile information, photographs, preferences | Life of the account |
| Chat messages | Life of the account, or earlier: a match with no activity for 90 days is closed and its messages are removed for both members |
| Incomplete sign-ups | Deleted after 30 days of inactivity |
| Waitlist entries | Deleted after the single open-city notification is sent, or earlier upon request |
| Date check-in responses | Life of the account; deleted with your other match records when the account is deleted |
| Usage analytics events | Deleted after 24 months |
| Invite link open records | Deleted after 24 months |
| Calendar tokens and free/busy windows | Deleted upon calendar disconnection or account deletion |
| Facial template of a banned account | Retained following a permanent ban for serious misconduct, to prevent the banned individual from returning (see Biometric Information Policy) |
| Moderation, safety, and audit records | Retained after related accounts close, as needed for safety and legal compliance |
7. Account Deletion
You may delete your account at any time in Settings. Upon account deletion:
- Your profile, photographs, preferences, matches, and messages are deleted;
- Any verification reference image still within its 30-day retention window is deleted immediately; and
- Your sign-in credentials are deleted.
We retain the following after account deletion: records we are legally required to keep or that are needed for safety purposes (for example, the record that a report was filed and resolved); records of consents you provided; and, only for accounts permanently banned for serious misconduct, the facial template described in the Biometric Information Policy.
8. Data Security
We maintain administrative and technical safeguards designed to protect personal information. All access to member data passes through our servers; the application does not have direct access to other members' data. Verification images are encrypted at rest with a dedicated key. Calendar connection tokens are stored in an encrypted vault and are never stored in plain text. Staff access to member data is restricted, individually authorized, and recorded in an audit log.
No method of transmission or storage is completely secure. If a breach affects your information, we will notify you as required by applicable law.
9. Your Rights and Choices
- Access and correction. Your profile information is visible and editable in the application.
- Deletion. You may delete your account in Settings at any time, as described in Section 7.
- Location. You may enter your city manually instead of using the device location check.
- Calendar. You may disconnect a connected calendar at any time in Settings; disconnection deletes the associated tokens.
- Notifications. You may disable notifications in your device settings and may hide message previews in the application's settings.
- Verification consent. Express consent is requested before biometric verification. If you decline, verification cannot be completed and the Services will not be available, because all member profiles are verified.
- Requests. You may submit access, correction, or deletion requests to support@novidate.com, whether or not such rights are required by the law of your state. We respond within 30 days.
Depending on your state of residence, state law may grant you rights to access, correct, or delete personal information. The choices described in this section are available to all users regardless of state of residence.
10. Cookies and Website Data
The Novi application does not use cookies. The application collects the usage and crash information described in Sections 2.2, 4, and 5.1; it does not use advertising or cross-site tracking technologies. The novidate.com website does not set tracking or advertising cookies and does not use third-party analytics services. The invite link records described in Section 2.5 are kept on our own servers; they involve no cookie and no identifier of the person opening the link. Because we do not track visitors across websites, browser Do Not Track signals do not change how the Services behave. If these practices change, we will update this Privacy Policy before the change takes effect.
11. Age Requirement
The Services are restricted to individuals 21 years of age or older. Sign-ups by individuals under 21 are refused and the associated data is deleted. If we learn that an account belongs to an individual under 21, the account is removed.
12. Scope
The Services are offered in the United States and are currently available only in the Atlanta, Georgia area. The practices described in this Privacy Policy apply to all users of the Services.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Services before the changes take effect. The current version is available at novidate.com/privacy.
14. Contact Us
Novi Connections Inc.
support@novidate.com