Privacy Policy
Last updated: September 2026
This Privacy Policy applies to all users worldwide. By using GoFitDaddy, you acknowledge that you have read and understood this policy. This app is intended for adults aged 18 and over only.
1. Introduction and Data Controller
Martrick GmbH (“we”, “us”, “our”) operates the GoFitDaddy app (“GFD”, the “App”) and is the controller of your personal data. We are committed to protecting your personal data and complying with applicable data protection laws worldwide, including the EU GDPR, the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Brazil’s LGPD, and other applicable privacy laws.
- Company
- Martrick GmbH
- Address
- Marcusallee 16, 28359 Bremen, Germany
- Data Protection Officer
- support@gofitdaddy.com
2. Data We Collect
2.1 Data You Provide
- Account information — username, email address, date of birth. We do not ask for or store a phone number.
- Profile information — photos and videos, albums, bio, status, gender identity, sexual orientation, pronouns, body type, fitness level, tribe and interest tags, what you are looking for, and any health information you choose to add
- Communications — messages (text, photo, video, voice), taps, reports and support tickets
- Verification data — a selfie, if you complete optional age assurance. The selfie is passed to our age-estimation provider and is never stored by us; we keep only the resulting age band and outcome.
- Payment information — none. Apple and Google are the merchants of record for every purchase. Card numbers, billing names and billing addresses never reach us. We store only a store-issued transaction identifier, the product bought, and the dates it covers.
2.2 Data Collected Automatically
- Device information — a push-notification token, so we can deliver notifications you have enabled. We do not collect advertising identifiers and the App contains no advertising or attribution SDKs.
- Usage data — none. The App contains no analytics SDK, and we do not measure which features you use or how long you spend in them.
- Location data — approximate location only, if you permit it. Your device rounds the GPS fix to roughly 100 metres before it is sent, and our server rounds it again on arrival, so an exact position is neither transmitted nor stored. Distances shown to other users are banded, never precise.
- Log data — our servers keep standard technical logs (IP address, request path, timestamp) for security and abuse prevention
2.3 Sensitive Data
We collect certain special categories of personal data, including sexual orientation and gender identity, which you voluntarily provide. We process this data based on your explicit consent. You may withdraw consent at any time.
3. How We Use Your Data
- Providing & improving the App · Contract performance
- Retention: duration of account
- Account registration · Contract performance
- Retention: duration of account + 3 years
- Content moderation & safety · Legitimate interest / Legal obligation
- Retention: up to 7 years
- Age verification · Legal obligation / Consent
- Retention: until verified, then deleted
- Customer support · Contract performance
- Retention: 3 years after resolution
- Sending service notifications · Contract performance
- Retention: duration of account
- Marketing (with consent) · Consent
- Retention: until withdrawn
- Legal compliance & reporting · Legal obligation
- Retention: as required by law
- Fraud prevention & security · Legitimate interest
- Retention: up to 5 years
4. Data Sharing and Third Parties
We do not sell your personal data. We may share data with:
- Service providers — cloud hosting, content moderation, age assurance (where used), and the sub-processors listed in section 4.1
- Law enforcement — when legally required, including mandatory CSAM reporting to NCMEC (USA), BKA (Germany), and equivalent national authorities
- Payment processors — Stripe or equivalent — subject to their own privacy policies
All third-party processors are bound by Data Processing Agreements (DPAs) in accordance with GDPR Article 28.
4.1 Current Sub-processors
We currently use the following sub-processors to operate the App. This list may change; we will update it here:
- Elestio / Hetzner Online GmbH (Germany) — database, authentication, file storage and backend hosting. The App runs on a dedicated, self-hosted instance in a data centre in Nuremberg, Germany. Your account, profile, photos and messages are stored there, inside the EU.
- OpenAI (United States) — automated moderation of images, video frames and message text; transcription of voice messages for moderation; optional AI conversation suggestions
- Microsoft PhotoDNA — hash-matching against known child sexual abuse material — integrated and pending activation by Microsoft
- Yoti (United Kingdom) — privacy-preserving facial age estimation, used only if you complete optional age assurance — integrated and not yet activated
- DeepL SE (Germany) — optional in-chat and interface translation
- OpenStreetMap / Nominatim — turning a typed city or address into map coordinates
- Apple and Google — merchants of record for all in-app purchases and subscriptions. They take the payment, hold the payment data and handle refunds; we receive only a transaction identifier and what it entitles you to.
- Stripe — event-ticket processing only, where a host sells tickets for their own event. Not used for in-app purchases, and currently not enabled.
- Expo (United States) — push-notification delivery
- STRATO AG (Germany) — delivery of account and support email — support tickets themselves are handled in-house, not by an external help desk
We no longer use Mistral AI, Sightengine or RevenueCat, and we no longer host any user data in the United States.
4.2 Data sources & attribution
Some reference information in the App is based on the following public sources. GoFitDaddy is not affiliated with or endorsed by them:
- Equaldex & publicly available legal information — country LGBTQ+ legal status and rights data
- World Bank — country income classification (used only for pricing guidance)
- OpenStreetMap contributors — map and place data (© OpenStreetMap, ODbL)
5. International Data Transfers
Your account, profile, photos, albums and messages are stored on our own servers in Nuremberg, Germany, and do not leave the EU in the ordinary course of using the App.
Data leaves the EU only in these specific cases:
- Moderation — an image, a video frame, message text, or a transcript of a voice message is sent to OpenAI in the United States to be checked. It is used only for that check.
- Push notifications — a notification token and the notification text are sent to Expo in the United States to deliver the message to your device.
- Age assurance — if you complete optional age assurance, the selfie is sent to Yoti in the United Kingdom, which has an EU adequacy decision.
- Purchases — Apple and Google process the payment under their own terms and privacy policies.
For those transfers we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable, including the United Kingdom
For users in Brazil, South Korea, China, and India, additional local law requirements may apply. We comply with applicable data localisation requirements.
6. Your Rights
6.1 Rights Under GDPR (EU/EEA/UK Users)
- Right of access — request a copy of your personal data
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure — request deletion of your data (“right to be forgotten”)
- Right to restriction — limit how we process your data
- Right to data portability — receive your data in a structured format
- Right to object — object to processing based on legitimate interest
- Rights related to automated decision-making and profiling
- Right to withdraw consent at any time without affecting prior processing
6.2 Rights Under CCPA/CPRA (California Users)
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to opt-out of the sale or sharing of personal information
- Right to non-discrimination for exercising your rights
- Right to correct inaccurate personal information
- Right to limit use of sensitive personal information
6.3 Rights Under LGPD (Brazilian Users)
- Confirmation of the existence of processing
- Access to data, correction, anonymisation, blocking or deletion
- Data portability and information about sharing
- Right to revoke consent
6.4 Rights Under Other Jurisdictions
Users in Australia, Canada, Japan, South Korea, Singapore, and India also have rights under their respective local laws. Please contact us to exercise any applicable rights.
6.5 How to Exercise Your Rights
To exercise any of your rights, contact us at: support@gofitdaddy.com. We will respond within 30 days (or sooner as required by applicable law). We may need to verify your identity before processing your request.
7. Data Security (Technical & Organisational Measures)
Because we process special categories of personal data (such as sexual orientation and approximate location), we apply a heightened, risk-based level of protection under Art. 32 GDPR. Our technical and organisational measures are designed to meet or exceed the security level that is customary for comparable dating and community applications.
7.1 Encryption
- All data is encrypted in transit using TLS 1.2/1.3; HTTPS is enforced.
- All data is encrypted at rest (AES-256) in both the database and media storage.
7.2 Access control & data isolation
- Row-level security: every request is authenticated and each user can access only their own data. Privileged service credentials are never shipped inside the app.
- Least-privilege access for staff and administrators; administrative access to production data is logged in an audit trail.
- Sensitive processing is isolated to dedicated providers — identity documents for age verification are handled by a specialist provider and are not stored long-term by us.
7.3 Content safety & abuse prevention
- Detection of child sexual abuse material using Microsoft PhotoDNA.
- AI-assisted photo moderation keeps explicit content out of public areas of the app.
- Rate limiting and automated risk assessment on sensitive operations and at sign-up.
7.4 Safety features you control
Especially for users in higher-risk regions, we provide additional protective tools: stealth mode, an emergency data wipe, a trusted-contacts allowlist, automatic stealth in high-risk locations, screenshot alerts in chat, expiring messages, and use of approximate rather than exact location.
7.5 Availability & recoverability
- Managed, geo-redundant infrastructure with automated backups and point-in-time recovery.
7.6 Organisational measures
- Data minimisation and defined retention periods; complete (hard) deletion of your data when you close your account.
- Data-processing agreements (DPAs) are in place with all sub-processors.
- Regular security and code reviews; our controls are oriented to recognised standards such as ISO 27001. Confidentiality and data-protection obligations apply to anyone with access.
7.7 Incident response
- We maintain an incident-response procedure and will notify the competent supervisory authority within 72 hours — and affected users where required — of becoming aware of a personal data breach, in line with Art. 33/34 GDPR.
No method of transmission over the internet or electronic storage is ever 100% secure, but we continuously work to protect your data and to improve our safeguards.
8. Children’s Privacy
Our App is strictly for users aged 18 and over. We do not knowingly collect data from anyone under 18. If we discover that a user is under 18, we will immediately delete their account and associated data. If you believe a minor has registered, please contact us immediately.
9. Cookies
We use cookies and similar tracking technologies. Please refer to our separate Cookie Policy for full details. You can manage your cookie preferences at any time through your device or browser settings, or through our in-app privacy settings.
10. Supervisory Authorities
You have the right to lodge a complaint with a supervisory authority. Key authorities:
- Germany / EU — Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen — www.datenschutz.bremen.de
- UK — Information Commissioner’s Office (ICO) — www.ico.org.uk
- USA (California) — California Privacy Protection Agency — www.cppa.ca.gov
- Brazil — Autoridade Nacional de Proteção de Dados (ANPD) — www.gov.br/anpd
- Australia — Office of the Australian Information Commissioner — www.oaic.gov.au
- Canada — Office of the Privacy Commissioner — www.priv.gc.ca
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the App or by email. The date at the top of this policy indicates when it was last updated. Continued use of the App after changes constitutes acceptance of the updated policy.
12. Contact Us
- Company
- Martrick GmbH
- Address
- Marcusallee 16, 28359 Bremen, Germany
- Data Protection Officer
- support@gofitdaddy.com