How Doppel handles your data.
Doppel is a social app for adults. To match you, we read the taste signals in your own TikTok or Instagram data (what you watch, search for and follow), turn them into a taste profile, and delete the raw file. We never read your messages on those platforms, we never sell your data, and we do not use it for advertising. You can delete your account and everything we hold in the app, or by emailing hello@getdoppel.app. You must be 18 or over to use Doppel.
- 1. Who we are
- 2. What this policy covers
- 3. Adults only
- 4. What we collect and why
- 5. Your feed data, in detail
- 6. Sensitive information
- 7. How matching works
- 8. Our legal grounds
- 9. Who we share data with
- 10. Where data is stored
- 11. How long we keep things
- 12. Your rights
- 13. Deleting your account and data
- 14. Security
- 15. This website, cookies and analytics
- 16. Complaints
- 17. Changes to this policy
- 18. Contact
1. Who we are
Doppel is made by Doppel Ltd, a company registered in England and Wales under company number 17456891, with its registered office at 1 Park Drive, London, England, E14 9BB. Doppel Ltd is the data controller for the personal data described in this policy. In this policy, "Doppel", "we" and "us" mean Doppel Ltd.
Questions about your data go to hello@getdoppel.app. You can also write to the registered office above. Doppel Ltd is registering with the UK Information Commissioner's Office (ICO) as a data controller; the registration reference will be published here once the ICO issues it.
2. What this policy covers
This policy covers the Doppel mobile app for iOS and Android (including any beta or pre-release version), the website at doppel.dating, and any email you exchange with us. It applies to everyone who uses the app or the website. It does not cover TikTok, Instagram, Apple or Google themselves: each of those has its own privacy policy for what happens on their side.
3. Adults only
Doppel is for people aged 18 or over. We ask for your date of birth when you create an account and we do not let anyone under 18 register. We may add an additional age check with a specialist age-assurance provider; if we do, we will name the provider in section 9 before it goes live and explain exactly what it sees.
We do not knowingly collect data from anyone under 18. If we learn that an account belongs to someone under 18, we close the account and delete the data. If you believe someone under 18 is using Doppel, email hello@getdoppel.app. Our child safety standards set out how we handle these reports.
4. What we collect and why
The table lists every category of personal data the app or website can collect, where it comes from, what we use it for, and our legal ground under UK data protection law (the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025). Optional items are marked.
| Data | Where it comes from | What we use it for | Legal ground |
|---|---|---|---|
| Account details: email address, name, date of birth, sign-in credentials or one-time sign-in link, phone number (optional) | You, when you sign up | Create and secure your account, confirm you are 18 or over, send account and safety emails | Contract; legal obligation (age) |
| Profile: photos, short written prompts, gender, who you want to meet, age range you want to meet, the area of London you are in, and optionally your university, course and height | You, when you build your profile | Show your profile to other members, filter who you see and who sees you | Contract; explicit consent where a field could reveal your sexual orientation (see section 6) |
| Feed data: watch history, searches, shares, hashtags, the platform's own inferred interest categories, who you follow, and (only if you upload an export file) likes and favourites | TikTok, when you authorise a transfer through TikTok's Data Portability API (when available); or a data export file from TikTok or Instagram that you upload yourself | Build your taste profile, match you with people whose feeds overlap yours, show you what you have in common with a match, and keep people you already follow from seeing you (see section 5) | Consent; explicit consent for the sensitive categories in section 6 |
| Taste profile: weighted interest categories, a list of creators you both follow and watch, and activity-rhythm statistics derived from your feed data. No raw video history is kept in it | Derived by us from your feed data | Matching, and explaining a match | Consent (as above) |
| Sensitive interest categories (religion, politics, health-related topics, LGBTQ+ culture, sexual content), only if you switch them on | Derived from your feed data, off by default | Improve matching for people who opt in. Never shown to other members | Explicit consent, withdrawable in Settings at any time |
| Activity in the app: likes, skips, matches, hidden creators, settings, reports and blocks you make or receive | Generated as you use the app | Run the service, keep it safe, act on reports | Contract; legitimate interest (safety and abuse prevention) |
| Messages you send to and receive from your matches | You and your matches | Deliver your conversations; review a conversation when one of you reports it | Contract; legitimate interest (safety) for reviewing reported conversations |
| Outcome signals: whether two people matched, replied to each other, kept talking, or told us they met | Generated as you use the app, plus optional prompts you can ignore | Measure whether our matching works and improve it. Used in pseudonymised form: your name, email and photos are not part of it | Legitimate interest (improving the service); you can object at any time |
| Device and technical data: device type, operating system and app version, push notification token, IP address, crash reports and basic app logs | Your device, automatically | Make the app work, send notifications you have turned on, fix crashes, prevent abuse and rate-limit attacks | Contract; legitimate interest (security) |
| Support correspondence: emails you send us and our replies | You | Answer you, and keep a record of what was agreed | Legitimate interest (customer support) |
What we deliberately do not collect. We do not access your device's precise location (the area of London is something you tell us). We do not read your contacts, your camera roll beyond the photos you choose, your microphone, or your other apps. We do not use advertising identifiers and we do not track you across other companies' apps or websites.
5. Your feed data, in detail
This is the part of Doppel that is different from other social apps, so it deserves its own section.
Two ways your feed data can reach us
- TikTok Data Portability transfer (when available). In the app you can authorise TikTok to send us a copy of your activity data and your profile's following list. TikTok shows you what will be transferred before you agree, and you can revoke the authorisation at any time in Doppel's Settings or in TikTok's own settings. Where you keep the authorisation on, we refresh the data periodically (roughly every three days) so your taste profile stays current; you can turn refreshes off in Settings.
- Your own export file. You can instead request a copy of your data from TikTok or Instagram and upload the file to Doppel yourself. We give step-by-step instructions in the app for requesting an export that contains only the categories we need.
What we keep from it and what we throw away
We keep only what matching needs: watch history, searches, shares, hashtags, the platform's inferred interest categories, the list of accounts you follow, and likes and favourites where they are in an export file. Everything else that a transfer or an export can contain is discarded at the moment we receive it and is never stored: direct messages (our export instructions tell you to leave them out entirely), login history, IP addresses and device identifiers, purchases and shop history, posts and drafts, biography text, birthdate, settings and contacts.
The raw transfer or export file is deleted as soon as we have built your taste profile, and in every case within 7 days of receiving it. What remains is the taste profile described in section 4.
People you follow
We use the list of accounts you follow for two things: to find shared taste with other members, and to keep you and the people you follow from seeing each other on Doppel. Hiding is on by default and you can un-hide specific people in Settings. Other members never see who you follow.
6. Sensitive information
UK data protection law gives extra protection to "special category" data: information about religion, political opinions, health, sex life and sexual orientation, among others. Doppel touches this in two places, and in both we rely on your explicit consent.
- Who you want to meet. Telling us the gender of the people you want to meet can reveal your sexual orientation. We use it only to decide whose profile you see and who sees yours. Other members see it only as far as it is implied by the fact that you appear in their feed.
- Sensitive interest categories in your feed. By default, we do not use any part of your feed that relates to religion, politics, health-related topics, LGBTQ+ culture or sexual content. If you want those parts of your taste to count towards matching, you can switch them on in Settings, individually or all at once. Switching them off again removes them from your profile. These categories are never displayed to another member, whatever your settings.
Content related to self-harm or eating disorders is excluded from processing altogether. It is discarded when your feed data arrives, it is never used for matching, and there is no setting to turn it on.
7. How matching works
Doppel compares taste profiles and shows you people whose feeds overlap yours, together with a plain explanation of what you share (for example, a creator you both follow or a topic you both watch a lot). This is automated profiling. It does not make any decision with legal or similarly significant effects on you: it only decides the order in which profiles are suggested, and every match still needs both people to say yes. The overlap score is a measure of shared taste; it is not a prediction of attraction, chemistry or how a relationship will go, and we never present it as one.
8. Our legal grounds
- Contract: the processing needed to give you the service you signed up for (your account, profile, matches and messages).
- Consent: reading your feed data, and keeping the taste profile derived from it. You give consent in the app and can withdraw it at any time in Settings or by email; withdrawing does not affect what was done before.
- Explicit consent: anything that could reveal special category data (section 6).
- Legitimate interests: keeping the service safe (acting on reports, preventing abuse, security logging), supporting you, and improving matching with pseudonymised outcome signals. We have weighed these against your interests and you can object (section 12).
- Legal obligation: confirming you are an adult, keeping records the law requires, and responding to lawful requests from authorities.
9. Who we share data with
We do not sell personal data and we do not share it with advertisers or data brokers. We share it only with the providers below, each under a contract that requires them to protect it at least as well as this policy does and to use it only on our instructions.
| Provider | What they do for us | What they hold |
|---|---|---|
| Supabase | Database, file storage and sign-in for the app (servers in London, UK) | Account, profile, taste profile, messages, activity, and the raw feed file for the short period before it is deleted |
| Cloudflare | Hosts this website and protects our domain | Standard web server logs (IP address, browser, pages requested) |
| Google Workspace | Our email | Anything you email us |
| Resend | Sends sign-in links and account emails on our behalf | Your email address and the content of those emails |
| TikTok | If you authorise a Data Portability transfer (when available), TikTok sends us the data described in section 5. TikTok also knows that you authorised Doppel | Governed by TikTok's own privacy policy on their side |
| Apple and Google | Distribute the app, deliver push notifications, and collect crash reports through their platforms | Push tokens, crash and diagnostic data, and whatever you have agreed to share with them directly |
If we add a provider that handles personal data (for example an age-assurance service, a photo-moderation service, or an AI service that helps sort video titles into interest categories), we will name it here before it goes live. Any AI service we use for categorising feed content would receive only titles, hashtags and category labels, never your name, email address, photos or messages.
We may also disclose data when the law requires it, to respond to a valid request from a court, regulator or law enforcement body, to protect someone's safety, or to enforce our terms. If Doppel Ltd is ever sold or merges with another company, your data would pass to the new owner under this policy, and we would tell you first.
10. Where data is stored
Your account, profile, taste profile and messages are stored in the United Kingdom (Supabase, London region). Some providers in section 9 may process limited data outside the UK: for example Apple, Google, Cloudflare and Resend operate globally. Where that happens we rely on the UK's adequacy regulations or on the UK International Data Transfer Agreement or Addendum, so that your data keeps the same protection wherever it is processed.
11. How long we keep things
| Data | Kept for |
|---|---|
| Raw feed transfer or export file | Until your taste profile is built, and never more than 7 days |
| Account, profile, taste profile, matches, messages, settings | While your account is open. When you delete your account, or ask us to close it, we delete them within 30 days; copies in backups are gone within 90 days |
| Reports, blocks and records of enforcement action | Up to 12 months after the account they relate to is closed, so that a banned person cannot simply return, and to meet our safety obligations |
| Outcome signals used to improve matching | Pseudonymised when your account closes and kept only in that form |
| Device data, logs and IP addresses | 30 days, unless part of a security investigation |
| Support emails | 12 months after the conversation ends |
| Records we must keep by law (for example a record that you consented, or a report we made to the authorities) | As long as the law requires |
12. Your rights
Under UK data protection law you can ask us to:
- give you a copy of the personal data we hold about you (access);
- correct anything that is wrong (rectification);
- delete your data (erasure), which you can also do yourself in the app (section 13);
- limit what we do with it (restriction);
- give you your data in a machine-readable form so you can take it elsewhere (portability);
- stop processing based on our legitimate interests (objection);
- withdraw any consent you have given, at any time, without affecting what was done before;
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you. Doppel makes no such decisions (section 7).
To use any of these rights, use the controls in the app or email hello@getdoppel.app from the address on your account. We reply within one month, and we may ask you to confirm your identity first so that nobody else can act on your account. There is no charge unless a request is clearly unfounded or excessive.
13. Deleting your account and data
Two routes, both free:
- In the app: Profile, then Settings, then Delete account. Confirm, and your account and data are deleted as set out in section 11.
- By email, without the app: send "Delete my account" to hello@getdoppel.app from the email address on your account. We confirm by reply and complete the deletion within 30 days.
Full instructions, including how to delete only your feed data or disconnect TikTok while keeping your account, are on our delete your account and data page.
14. Security
Data moves between your device and our servers over encrypted connections and is stored encrypted at rest. Access to the database is restricted by row-level security so that the app can only read a member's own records, and the raw feed file is written to a private storage path that only our processing job can read. Staff access to personal data is limited to what support and safety work needs, and is logged. No system is perfectly secure; if you spot a weakness, please tell us at hello@getdoppel.app and we will act on it.
15. This website, cookies and analytics
doppel.dating sets no cookies and runs no analytics, advertising or tracking scripts of any kind. Our host, Cloudflare, keeps standard server logs for security, and nothing else is recorded about your visit.
16. Complaints
If you think we have handled your data badly, please tell us first at hello@getdoppel.app. We acknowledge every data protection complaint within 30 days, look into it, and tell you the outcome and anything we have changed. You also have the right to complain to the UK regulator, the Information Commissioner's Office: ico.org.uk/make-a-complaint, telephone 0303 123 1113.
17. Changes to this policy
We will update this policy as Doppel develops, for example when we add a provider or a feature. The version number and date at the top change each time. If a change matters to you (a new purpose, a new category of data, or a new recipient) we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again. The version you agreed to is recorded against your account.
18. Contact
Doppel Ltd
1 Park Drive
London E14 9BB
United Kingdom
hello@getdoppel.app