Privacy Policy
Effective 16 August 2026. Plyr2 is operated by Hyperspace Media Group.
The short version. We collect what a dating app needs to work and not much else. We do not sell your data, and the app contains no third-party analytics or tracking. Your phone number is stored in a form we cannot reverse. Your exact location never leaves your phone. You can delete everything yourself, from inside the app, whenever you want. Advertising is planned for the public release. There is none in the app today, and section 4 says exactly what will change when it arrives.
1. Who we are
Plyr2 is a dating app operated by Hyperspace Media Group ("we", "us"). If you want to reach a human about anything in this policy, email support@hyperspacemediagroup.com. That address is monitored and we answer it.
2. You have to be 18
Plyr2 is for adults. You must be 18 or older to create an account, and we check the date of birth you give us at sign-up and refuse anything under 18. Your date of birth cannot be edited afterwards. Only your age, derived from it, is ever shown. If we learn that an account belongs to someone under 18, we delete it.
3. What we collect, and why
Your phone number
You register with a phone number, and we text you a six-digit code to confirm it is yours. Here is the part worth understanding:
We never store your phone number. We store a one-way cryptographic hash of it: a fixed-length fingerprint that can be matched against a number you type in, but cannot be turned back into the number itself. Even with complete access to our database, nobody can recover the phone numbers of our users, because they are not in there. The trade-off is real and we accept it: it means we cannot text you unless you supply the number again yourself.
Your password
Stored only as an Argon2 hash. We cannot see your password, and neither can anyone who obtains the database.
Your profile
Everything you choose to put on it, which is a lot, and all of which is optional except your name and date of birth: your bio, gender (including a self-described one), the game you're playing now and what you've played recently, interests, languages, religion, education, job title and employer, height, diet, allergies, pets, whether you have kids, and your answers about smoking, drinking, cannabis and other substances. Also what you're looking for: your relationship intent and status, and which genders you want to see. These exist to match you with people and to be shown to the people you might match with. Some of them are sensitive by nature; you decide which ones to fill in, and you can clear any of them at any time.
Your location
Distance is the only thing matching needs, so distance is all we keep.
- If you let the app read your location, it is used once, on your device, to look up the ZIP code you are in. The coordinates are then discarded, and they are never stored on our servers.
- You can skip that entirely and type a ZIP code in yourself. Nothing is lost by doing so.
- What we store is that ZIP code and what it resolves to: your city, state, time zone, and the geographic centre point of the ZIP area, which is what distances are measured from.
- Other users see your city, your state, and a rough distance in miles. They are never given coordinates of any kind.
Your photos
Photos are stored on servers we operate. Two things happen to every photo on the way in: its embedded metadata is stripped (including the GPS coordinates that phones quietly bake into images, which on a dating app is a home address waiting to be published), and it goes through moderation before it can appear (see section 5). Photos are only ever served to signed-in users through our app; they do not sit at public web addresses that can be found or shared.
What you do in the app
Your swipes, matches, messages, compliments, love-credit balance and transactions, blocks, reports, and when you were last online. Swipes are recorded so we do not show you the same person twice; nobody is ever told that you passed on them.
Technical records
Our servers keep ordinary access logs, which include IP addresses, and we issue your device a session token so you stay signed in. These are used to run the service, to keep it up, and to detect abuse, rate-limiting a flood of sign-up attempts, for instance. Logs are kept briefly and are not used to build a profile of you.
4. Advertising, and what we will not do with your data
Today there are no ads in Plyr2, and there are none in the TestFlight build. We intend to introduce advertising when the app reaches general release. It is how a service with no boosts and no paywall pays for itself. We would rather tell you that now than surprise you with it later.
When advertising does arrive, these are the commitments that come with it:
- We update this policy before the first ad appears, not after, naming the ad provider we use.
- Advertisers do not get your profile data. Not your photos, your messages, your relationship intent, your gender, your religion, your health-adjacent answers, or anything else you filled in. We will not build targeting segments out of who you are or what you are looking for.
- We still will not sell your personal data. Showing you an ad and selling your data are different things, and only the first one is on the table.
- Where the law requires your permission first (iOS App Tracking Transparency, or consent under GDPR), we will ask, and a refusal will be respected rather than routed around.
Be aware of the honest limitation: ad providers collect their own information from the devices they serve, typically a device advertising identifier and general usage signals. That is their processing, disclosed in their own policy, and it is the part we will name here specifically once a provider is chosen.
What we do not do, ads or no ads
- No analytics or tracking in the app. There is no Google Analytics, no Firebase, and no third-party tracker of any kind inside Plyr2 today. We removed the one analytics tag that was there before launch, because the screens you visit in a dating app reveal things (your relationship style, your gender identity, your religion) that we are not willing to hand to anyone.
- No selling or sharing of personal data, for money or otherwise, to anyone, for any purpose.
- No paid visibility. We do not sell boosts, and we cannot. The feature does not exist. Everyone you could match with sees your profile. Advertising does not change this: the ranking is not for sale.
5. Photo moderation, and who can see your photos
Every photo is screened before it appears anywhere. An automated check runs first. If a paid moderation service is enabled on our account, the image may also be sent to Amazon Web Services' image-moderation API for a second opinion; AWS processes the image for that check and does not keep it. Anything the automatic checks do not clear waits in a queue for a human moderator on our team to look at.
So: yes, a person at Hyperspace Media Group may see a photo you upload, and may read a conversation that has been reported to us. That is the price of the safety features, and we would rather say it plainly than bury it. Moderators do not browse conversations that have not been reported.
6. The services that ever see any of this
The complete list. Each one gets the minimum needed to do its job:
- ClickSend: delivers your verification SMS, and therefore receives your phone number at the moment you type it. It never receives anything else about you.
- Amazon Web Services: image moderation, when enabled. Receives the photo being checked, and nothing identifying you.
- IGDB / Twitch: the game catalogue behind the "what are you playing" search. Our server performs those lookups, not your phone, so IGDB receives a search term but never your IP address or any identifier of yours.
- Google Analytics: on this website only, where it measures how many people reach the waitlist page. It is not in the app. If you are only ever in the app, Google is not involved at all.
We use no other processors, and there is no advertising network anywhere in this list. Some of these providers operate in the United States, so data sent to them is processed there. Our own backups are encrypted before they leave our servers and stored with a European hosting provider.
7. When we would hand something over
Only in three situations: when the law actually requires it and we have satisfied ourselves that it does; when it is necessary to protect somebody from harm; and when you ask us to. We will tell you if we are compelled to produce your data unless we are legally forbidden from telling you.
8. How long we keep things
- Your account: until you delete it.
- Deleting your account (Me tab, in the app, no reason required, no email to us needed) removes your profile, your photos from both our database and our file storage, your session tokens, your swipes, your matches, your messages, your blocks and your partner links.
- Reported conversations are the exception. If a conversation has been reported, it is kept after the account is deleted, because otherwise anyone could erase the evidence of what they did by deleting their account. It is kept for safety and moderation, and nothing else.
- Conversations you hide are permanently purged 90 days later, unless they were reported.
- Backups roll off on their own schedule, so a deleted account can persist in an encrypted backup for a short period after deletion before being overwritten.
9. Your rights
Wherever you live, you can ask us to show you what we hold about you, correct it, or delete it, and we will do it. Deletion you can do yourself, instantly, in the app.
If you are in the UK or EU, the GDPR gives you those rights explicitly, along with the right to object to processing, to restrict it, and to receive your data in a portable form. We process your data to provide the service you signed up for (contract), to keep users safe and prevent abuse (legitimate interests), and, for the optional device-location lookup and for any sensitive detail you choose to add to your profile, because you consented, which you can withdraw by clearing the field or by turning the permission off in your phone's settings.
If you are in California, you have the right to know what we collect and to have it deleted. We do not sell or share personal information as the CCPA uses those terms, so there is nothing for you to opt out of.
To exercise any of this, email support@hyperspacemediagroup.com. We will not make you jump through hoops, and we will not charge you.
10. Cookies
This website uses Google Analytics cookies to count visits to the waitlist page. The app uses local storage on your device to keep you signed in; that is not a tracking cookie and it is not readable by anyone else.
11. Security
Traffic is encrypted in transit. Passwords are hashed with Argon2, phone numbers are stored only as irreversible hashes, photo storage keys are not exposed by our API, and photos require an authenticated request to view. No system is perfect, and anyone who tells you otherwise is selling something. But the design above is deliberately built so that a breach yields as little usable information as possible.
12. Changes
If we change this policy in a way that matters, we will update the date at the top and tell you in the app before the change takes effect. We will not quietly start selling data and mention it in a footnote.
13. Contact
support@hyperspacemediagroup.com. Hyperspace Media Group.