Legal
Last updated September 23, 2026
Your account email, and the profile you build. That starts with your name, your photos and your date of birth, which we store as a date, not just an age, because we use it to show your age and to enforce the rule that Lark is 18 and over. The rest of the profile is optional and you choose what to fill in: gender, who you are looking for, pronouns, orientation, height, languages, job, education, interests, your bio, your prompt answers, and lifestyle answers about drinking, smoking, children and pets. Three of those optional fields are ones many people consider sensitive, so we name them plainly rather than leaving them inside the word “profile”: your religion, your politics, and your ethnicity. Nothing requires them, they appear on your profile exactly as you write them, and you can clear any of them at any time in Profile, Edit. We also store the pitches and messages you send and receive, your match history, and basic usage events. Location is the city on your profile and it is optional. You can type it, skip it, or press “Use my current location”. To be plain about it: with your permission, the app may access your device’s location, and it stores only an approximate value. If you allow it, the coordinates are snapped on your own device to a grid of roughly three kilometres before anything is sent anywhere. We then look up which place that snapped point falls in, and every coordinate we save is snapped to that same grid, so the location on your profile is always an approximate, city-level point. An exact fix is never transmitted to us and never stored. If you decline the permission we tell you so and let you type your city instead; we do not quietly look you up by IP address in place of the answer you just declined. The app works fully without any of this, you only lose distance matching. Prompts can be answered out loud. If you record one, the app asks for permission to use your microphone and stores the recording with your profile, where anyone who can see your profile can play it; re-recording or clearing the prompt removes it. Inside a match chat you can send photos and voice notes, and those are stored with the conversation the same way a text message is. If you use Duo, the couple profile you build with your partner, meaning your shared bio, photos and prompts, and the messages in a double date group chat, are stored on the same terms as everything else here. When a matchmaker likes a photo or a prompt they can attach a short comment, and we store that comment along with which photo or prompt it was about. If you invite a matchmaker by SMS we pass the number you typed to our SMS provider, Twilio, to deliver that one message, and we do not keep the number ourselves. What we keep is a one-way fingerprint of it, for up to 30 days, and only so that the same person cannot be invited over and over. We never read your contacts. Before you have an account, our pre-launch waitlist stores the email you submit, any referral code and the link source you arrived from, and any optional details you choose to add after joining (how you heard about us, whether you’d join as a dater or matchmaker, and your city). We use these to send your invite, credit whoever referred you, understand which channels bring people in, and plan where to launch. When you join the waitlist we also record the country your connection appears to come from, worked out from your IP address, which we use to decide how many confirmation reminders you are owed and, if you are outside the United States, to route you to a short interest form instead (see “Where we operate” below). It is a country only, never a city or an address. We also briefly log IP addresses and send records to prevent abuse and duplicate emails.
To run the product: showing your profile to matchmakers who browse, delivering pitches and messages, powering match features, and sending you notification emails about new pitches and matches. We don’t sell your data, and we don’t share it with advertisers. We also use activity signals, like how many introductions someone has recently received, to decide which profiles to feature to matchmakers who browse. We never show matchmakers those counts. Email privacy@larkdating.com to opt out of being featured.
Several features use AI, and all of them go to the same provider, Anthropic’s Claude. Text first: suggested openers, the matchmaker’s pitch review, and Solo Lark, which drafts a full pitch for people who do not have a matchmaker yet, all send relevant profile text, like prompts and interests, and the pitch being worked on. Before a pitch, an intro, or a chat message is delivered, its text is screened by Claude to block harmful or abusive content, which means the messages you send in a match chat and in a Duo group chat pass through that check on their way. Then images, and this is the part worth being exact about: every photo you upload to your profile is sent to Claude’s vision model to check that it shows a real person and nothing explicit, and so is every image you send in a chat, before it is delivered. When that check cannot run, the image is still delivered and we record the failure rather than treat it as a clean result. Photo verification, if you choose to use it, sends the live selfie you submit alongside your profile photos to the same vision model to confirm you are a real person; the selfie is checked in the moment and not stored. Semantic matching, which is not switched on, would send profile text to Voyage AI to build embeddings that help rank who you might click with, and no profile has one today. In every case the content is used only to produce that result and isn’t used by those providers to train their AI models. Providers may hold content briefly for their own abuse monitoring under their standard terms; we don’t keep a copy beyond what’s described here.
Verification is optional. If you choose to verify, you take a live selfie and we send it, together with your profile photos, to Anthropic’s Claude vision model for a single comparison whose only purpose is to confirm that a real person who matches your photos is setting up the account. That comparison happens in the moment: we do not store the selfie, we do not create or keep a faceprint, face template, or other biometric identifier from it, we do not use it to identify you anywhere else, and we do not sell or disclose it. Because we do not retain it, there is no biometric retention period beyond “not retained.” You are not required to verify to use Lark, and declining verification does not remove your access to the core app.
We record how introductions go: which pitches are accepted, which lead to messages, and which lead to a meeting. We keep that outcome data, along with the pitch text it belongs to, so we can improve how we match people, and it stays inside Lark. Today we do that with ranking rules we write ourselves. Lark does not train a matching model on this data yet, and while semantic matching is switched off the profile embeddings described above are not part of it. If and when we do train a matching model on this data, we will do it under this policy, and the opt-out still applies. You can opt out any time in Settings → Privacy & safety → Data preferences. Opting out keeps your introductions out of the dataset we build for this purpose and out of any model we later train from it, and it does not change how the app works for you.
Matchmakers browsing the app can see dating profiles (that’s the product). No person other than you and your match can read your messages, though they are screened automatically for harmful content as described above. One exception, and it is yours to trigger: if you report someone from a chat, their recent messages in that chat are attached to the report so our safety team can see what happened. Yours are not attached. No one at Lark Dating reads a conversation that has not been reported, and we produce the contents of messages only where valid legal process compels us to, or, in an emergency involving a good faith belief of a risk of death or serious physical injury, where the law permits us to disclose voluntarily, which our Law Enforcement Guidelines describe. Read activity is private, the other person never sees whether you’ve read their message. Rejections are never shown to the person who was pitched for.
The app itself is hosted by Vercel, which sees the network requests your device makes to us, including your IP address, and provides both the approximate city we use when you tap the location button and the country-level signal we record when you join the waitlist. Data is stored with Supabase (database, authentication, and photo storage). Payments are processed by the Apple App Store and Google Play (via RevenueCat), and, for web purchases, by Stripe. We never see your card number. Notification and account emails are sent via Resend, and matchmaker SMS invites are delivered by Twilio. AI features use Anthropic (Claude) and Voyage AI as described above. When you search for your city, the place name is sent to LocationIQ and OpenStreetMap to turn it into an approximate location, and if you use the location button it is the rounded coordinates that are sent to them instead. Our waitlist and some forms are protected from bots by Cloudflare Turnstile, which checks a challenge token from your browser. Push notifications are delivered through Google Firebase Cloud Messaging on Android, Apple’s Push Notification service on iPhone and iPad, and your browser’s own push service if you turn notifications on for the web. Whichever applies, it receives your device’s push token and the content of the notification. We use Sentry to monitor errors so we can fix crashes, and PostHog to understand which features people actually use. We don’t sell your data or share it with advertisers.
Your profile, your matches and your messages stay until you delete them or delete your account, because they are the product. The records that exist to run the service clean themselves up on a fixed schedule instead: product analytics events are deleted after 90 days, the step-by-step records of how people move through sign-up after 90 days, the log of emails we have sent you after 60 days, the copies of those emails themselves after 30 days, the fingerprints of SMS invite recipients after 30 days, and the short-lived counters that stop abuse of our own forms after 2 days. Our record of a moderation decision, meaning what we did about a pitch we held for review or a photo we could not check, when, why, and which accounts were involved, is deleted after 2 years, and so is our record that we told members who had exchanged messages with an account we banned for fraud, which the law requires us to send and to be able to show we sent. We briefly recorded that a matchmaker had your profile in the cards they were shown, to tell you how many had you in their deck that week. We stopped doing that and removed the feature; any record of it still in our systems is deleted within 14 days and was only ever read as a count, never as a list of who. Photos live in storage until you remove them or delete your account.
Profile → Settings → Delete account permanently removes your profile, photos, prompts, voice answers, matches, messages, pitches and usage records, and deletes your login. Six things survive it, and they are the same six listed on our delete-account page. An intro you wrote that already brought two other people together stays in their conversation, with your name taken off it, because it is the only explanation they have for why they are talking. If you filed or were named in a safety report, we keep that report on file, including both accounts’ identifiers, so a report cannot be erased by either side deleting their account. If a pitch written by you, for you or to you was held for review, we keep our record of what we decided about it, when, why and which accounts were involved, for the 2 years above; the words of the pitch come out of that record as soon as any of those accounts is deleted. We keep the billing and transaction records that tax, accounting and chargeback rules require us to keep. And usage events we have already recorded stay in the analytics log with your identifier stripped out of them, until the 90 day window above deletes them anyway. And if you had joined our waitlist with the same address, one suppression line for that address stays: the address itself and the date it was unsubscribed, kept only so we never email it again. Everything else on that line, including where you heard about Lark, the country your signup came from, your locale, who referred you and what you said you were interested in, is cleared at the same time. There’s also an Account Refresh option that resets discovery history without deleting you.
We use a small number of strictly-necessary cookies to keep you signed in. We also use privacy-friendly product analytics to understand feature usage in aggregate, and it is on by default in most of the world. In the UK, the EEA, Switzerland and the European territories and dependencies we treat the same way, it stays off until you turn it on. We work out which of those applies from the country your connection appears to come from, and we do not store that with your account. Either way you can change it when you create your account, or at any time in Settings → Privacy. We record which features are used and how an introduction goes, including which accounts were involved, never the content of your messages or your matches. We don’t run third-party advertising trackers and don’t sell or share your data for cross-context behavioral advertising. Lark also keeps a few preferences on your own device, for example which profiles you have already seen, so the deck shows you new faces. That stays on your device, is never sent to us, and is cleared when you sign out.
Depending on where you live (e.g. the EU/UK under GDPR, or California under CCPA/CPRA), you can request access to your data, correct it, delete it, export a copy, or object to certain processing, without being discriminated against for asking. You can do most of this in-app (edit your profile, delete your account); for anything else email privacy@larkdating.com and we’ll respond within the timeframe the law requires. We don’t sell your personal information.
If you are a California resident, this section describes how the CCPA/CPRA applies. The categories of personal information we collect are described in “What we collect”: identifiers such as your email, account and profile content, your messages, approximate location, and device and log data. Because Lark is a dating product, some of what you may choose to put on your profile falls into what California treats as sensitive personal information: your sexual orientation, and the optional religion, politics and ethnicity fields, which map to religious or philosophical beliefs and to racial or ethnic origin. None of them is required to use Lark, and you can clear any of them in Profile, Edit. The live selfie used for optional verification is biometric information while the check is running; it is not retained, and no faceprint or template is created or kept from it. We collect it to provide the service you asked for, and we use sensitive personal information only for those purposes and as otherwise permitted by law, not to infer characteristics about you. We do not sell your personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of on that front and no “Do Not Sell or Share” link is required. California residents may request to know, delete, or correct their personal information, and to limit certain uses of sensitive personal information; we will not discriminate against you for exercising these rights. To make a request, email privacy@larkdating.com or use the in-app deletion described above. We may need to verify your identity before we act on a request.
Lark Dating, Inc. is based in the United States, and the dating service is offered only in the United States today; your information is processed here. If our systems place you outside the United States, you cannot create a Lark account, and you will be shown a short interest form instead, which asks only for your email so we can gauge demand for opening elsewhere later. Submitting that form is voluntary, we process the email (and the country your connection appears to come from) under our legitimate interest in evaluating where to expand, and you can ask us to delete it at any time by emailing privacy@larkdating.com. Because the service is not offered outside the United States, we do not rely on the GDPR, UK GDPR, or Swiss data protection law as a basis for running it, and no Standard Contractual Clauses or similar transfer mechanism apply to it. If a law in your country nonetheless gives you rights over the email you submitted through the interest form, see “Your rights” below.
We keep your data while your account is active. When you delete your account it’s removed promptly; limited records persist in encrypted backups, where we must keep them to comply with the law, resolve disputes, or enforce our terms, or where you filed or were named in a safety report, which we retain for trust and safety purposes even after the account it concerns is deleted. In rare cases we may have to decline a deletion request outright rather than only keep a residue of it: if your account is subject to a legal hold, meaning a law enforcement request, a preservation order or an active dispute obliges us to preserve it, we will refuse the deletion and tell you to contact us, and we will carry it out once the hold lifts.
We protect your data with encryption in transit and at rest, access controls, and reputable infrastructure providers. No system is perfectly secure, so we cannot guarantee absolute security. If a breach ever affects your personal information, we will notify you and any regulators as required by law.
Lark is for adults. You must be 18 or older to use it.
We may update this policy as the product changes. When we make a material change we will update the date above and tell you in the app or by email before it takes effect. Continuing to use Lark after an update means you accept the revised policy.
Lark Dating, Inc., a Delaware corporation, is the data controller for your information. Our mailing address is Lark Dating, Inc., 244 5th Ave Suite #1767, New York, NY 10001. Questions about your data? Email privacy@larkdating.com.
© 2026 Lark Dating, Inc. All rights reserved. Lark and the Lark logo are trademarks of Lark Dating, Inc.