Skip to content
Votails

Votails Privacy Policy

Effective Date: May 15, 2026
Last Updated: September 6, 2026

This Privacy Policy describes how Lash Digital Solutions LLC, a Florida limited liability company ("Votails," "we," "us," or "our"), collects, uses, discloses, and protects information when you use the Votails mobile application and any related websites or services (collectively, the "Service").

By creating an account or using the Service, you acknowledge that you have read and understand this Privacy Policy.


1. Who We Are and How to Contact Us

  • Operator: Lash Digital Solutions LLC, a Florida limited liability company
  • Sole member / manager: Jay Lash
  • Mailing address: 330 3rd St S Unit 1516, St. Petersburg, FL 33701, United States
  • Contact: support@votails.com

You may also send privacy-related correspondence to the email above with the subject line "Privacy Request."


2. Age Requirement

The Service is intended for users 18 years of age or older. We do not knowingly collect personal information from anyone under 13 (in compliance with the U.S. Children's Online Privacy Protection Act, "COPPA") and we do not allow anyone under 18 to register, regardless of jurisdiction. If you believe a minor is using the Service, contact us immediately and we will remove the account and delete associated data.


3. Information We Collect

We collect information in three ways: (a) information you provide directly, (b) information generated by your use of the Service, and (c) information from third parties.

3.1 Information you provide

  • Account information: your phone number, which is the identifier for your account — every Votails account is anchored to one phone number that you verify with a one-time text-message code — plus your first name and date of birth. There is no account email address and no username. If you link Sign in with Apple or Google Sign-In as a quick sign-in method, we receive the account identifier and identity token that provider issues, together with the name and email address you approve sharing at sign-in (Apple's may be a private relay address). We never collect, receive, or store a password.
  • Profile information: photos (up to six), gender, the genders you are interested in (which may indicate your sexual orientation), the city you enter, biography, interests, height, education and school, job title and employer, lifestyle attributes (drinking, smoking, cannabis, exercise), children status and preference, religion, political leaning, languages, relationship goal, profile prompts and answers, your Daily Rhythm quiz answers (how you plan, how often you like to hang out, whether you text or call, how you sleep, whether you are a morning person or a night owl, and your energy level), and two optional personality traits (easygoing or assertive; logical or emotional). Every quiz answer is optional. Your zodiac sign is derived from your date of birth.
  • Pet information: pet name, species/type, breed, description, pet photos, and your pet parenting style answers. You may also answer five optional questions about each pet — how it is around other animals, its energy level, its size, its experience with other animals, and any kinds of animal it reacts badly to. These are used to work out how your pet and another person's pet might get along; anything you skip is simply left out of that calculation rather than guessed at.
  • Preference information: the pet types you are open to and any allergies or dealbreakers, whether you are open to people with no pets, and your discovery filters (age range, distance, relationship goals, pet filters, verified profiles only, recently active only, and — on paid tiers — height, education, drinking, smoking, exercise, children, religion, how your deck is ordered, and a minimum compatibility percentage).
  • Communications: messages exchanged with other users, playdate proposals, and anything you send us by email.
  • Subscription information: Apple App Store and Google Play handle payment processing — we do not receive or store your credit card number. We receive a transaction identifier and subscription status from Apple/Google.
  • Reports and blocks: the reason and details you give when you report someone, and the list of people you have blocked.
  • Photo verification (optional): if you choose to verify your photos, a selfie you take in the app at that moment. We use it only to check that the face in the selfie matches the face in your profile photos, and we delete it immediately after that check (see Section 4). What we keep is the result — verified or not — and when it was checked. Verification is never required to use Votails.

3.2 Information generated by your use of the Service

  • Activity on the Service: your likes, passes, maybes, super likes, undone swipes, matches, unmatches, blocks, reports, subscription usage counts (for example, likes used today), and the time you were last active. On Premium we also store the weekly set of most-compatible profiles chosen for you, so that the set stays the same for the whole week rather than changing every time you open the app. These are recorded because they are how the Service works — not by an analytics tool.
  • Referral and promotion records: your referral code, the code you redeemed (which links your account to the person who referred you), whether each referral qualified, and whether your account holds a founding-member or referral credit. Used only to issue and audit promotional credit.
  • Technical information carried by every request: IP address, timestamps, and the app version and platform identified in standard request headers. We keep these in short-lived server logs for security, rate limiting, and reliability.
  • City-level location: we derive approximate coordinates from a city you type — your home city during onboarding or when editing your profile, and, if you use travel mode (Premium), the destination city you enter there. We never request your device's location permission and never collect GPS or other precise location from your phone. The city-level coordinates are used only to calculate the approximate distance between you and other users and to apply your distance filter. A travel destination is stored alongside your home city and never replaces it; clearing the destination restores your home city, and deleting your account deletes both.
  • Push notification device token: if you allow notifications, Apple (APNs) or Google (Firebase Cloud Messaging) issues your device a push token, which we store with your account so we can deliver new-message, new-match, new-like, playdate, and new-people notifications (the last tells you that people are available to see again after you have run out; it is sent only when that is true of your own search settings). It identifies your device to the notification service and nothing else; it is not an advertising identifier. We also store which notification types you have turned on or off in Settings. The token is removed when you sign out or delete your account, and a token the notification service reports as no longer valid is disabled.
  • On-device storage: the app stores your session and preferences on your device (UserDefaults on iOS, DataStore on Android). Our website, votails.com, does not set cookies (see the Cookie Policy).
  • Crash and diagnostic data: when the app crashes, freezes, or hits an unexpected error, a diagnostic report is sent to our error-monitoring provider, Sentry (Functional Software, Inc.). A report contains the technical stack trace, the sequence of screens and network request paths that led up to the problem, your device model and operating system version, the app version, and your account's internal identifier (a random ID that means nothing outside Votails). Our servers and website report their own unexpected errors the same way. A report never contains your name, phone number, photos, messages, profile content, or precise location: the app and our servers remove phone numbers, sign-in tokens, and request contents before anything is sent, no screenshots or screen recordings are ever captured, and Sentry is configured not to record your IP address. We use these reports only to find and fix problems (see Section 5). In addition, on a random 10% of app sessions and server requests, the app and our servers send performance samples to Sentry — how long screens, app launch, and network requests took, with the same device, operating-system, and app-version fields and the same internal identifier, and never the contents of a request. These help us find slowness, not just crashes. The website sends no performance samples. Sentry retains error reports and performance samples for 90 days, after which they are deleted.

What we do not collect: the app contains no analytics SDK and no advertising SDK — the only third-party diagnostic component is the crash-reporting library described above. We never read or use the advertising identifier (Apple's IDFA or the Android Advertising ID), and we do not ask for App Tracking Transparency permission because there is nothing to track.

3.3 Information from third parties

  • App stores: Apple and Google provide your subscription status, refunds, and limited account data (no full payment details).
  • Authentication providers (Apple and Google): if you link Sign in with Apple or Google Sign-In, the provider shares the name and email address you approve at sign-in (which may be a private relay address if you choose Apple's "Hide My Email"), along with a unique account identifier and identity token. We never receive your Apple or Google password or any other credentials for those accounts.
  • Phone verification provider (Twilio): we use Twilio Verify to deliver one-time verification codes by text message. Twilio processes your phone number for that purpose as our service provider; standard message and data rates from your carrier may apply.
  • Error-monitoring provider (Sentry): Sentry does not send us information about you. It receives the crash and diagnostic reports described in Section 3.2 and shows them to us; it is a service provider that processes that data only on our instructions.

4. Sensitive Personal Information

The Service necessarily collects information that may be considered sensitive under various privacy laws, including:

  • Sexual orientation (which may be inferred from the genders you say you are interested in)
  • Gender identity
  • Religious beliefs and political leaning (only if you voluntarily disclose them)

We do not collect precise geolocation (only the city you type, see Section 3.2).

Biometric information notice (optional photo verification)

Votails offers an optional photo-verification badge. If — and only if — you choose it and tap I agree on the consent screen, the app takes a selfie and our service provider Amazon Web Services (Amazon Rekognition) compares the facial geometry in that selfie with the facial geometry in your profile photos to tell us whether they match. That comparison uses biometric identifiers. This notice, together with the in-app consent screen, is our written biometric policy:

  • Purpose: solely to confirm that your profile photos depict you, so other users can see a "verified" badge. Never for identification of anyone else, advertising, or any other purpose.
  • Consent: we do not run the comparison until you have given express, informed consent in the app. You can decline and still use every other feature. You may withdraw consent at any time by contacting us; withdrawing consent removes the badge.
  • Retention and destruction: the selfie and any facial geometry derived from it are deleted immediately after the comparison completes — on success, on failure, and on error — and are never stored, displayed, or shared. We keep only the outcome (verified or not), the similarity score, and the time of the check, for as long as your account exists or until you withdraw consent, whichever is sooner. The facial geometry of your existing profile photos is computed transiently for the comparison and is likewise never retained separately from the photos themselves.
  • No sale, no disclosure: biometric information is never sold, leased, traded, or disclosed to anyone other than the service provider performing the comparison under contract, or as required by law.
  • Illinois, Texas and Washington residents: the rights and retention schedule above apply to you in full under the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and Washington's biometric identifier law.

Under the California Consumer Privacy Act (CCPA/CPRA), you have the right to limit the use of sensitive personal information. We use sensitive personal information only to (a) provide the matchmaking service you signed up for, (b) ensure platform safety, and (c) comply with law. We do not "sell" or "share" sensitive personal information for advertising.

We use sensitive personal information only with your knowledge and consent, as required to provide the matchmaking service you signed up for.


5. How We Use Information

We use the information described above to:

  • Create and maintain your account
  • Show you potential matches based on your preferences, and show your profile to people whose preferences you fit
  • Calculate compatibility scores, the compatibility percentage shown on profiles, "Why You Match" highlights, how well two people's pets might get along, and — on Premium — the weekly set of most-compatible profiles (a percentage compares only the questions both people answered; it is never a judgement of you alone)
  • Facilitate messaging and pet playdate proposals
  • Process subscriptions and renewals (via Apple/Google) and enforce the usage limits of your tier
  • Communicate with you about your account — one-time sign-in codes by text message, notices inside the app, and replies by email when you write to us. We do not send marketing communications.
  • Detect, investigate, and prevent fraud, scams, abuse, and policy violations
  • Respond to support requests
  • Comply with law, court orders, and lawful requests
  • Improve and develop new features (using aggregated and anonymized data)
  • Enforce our Terms of Service

We do not use your messages, profile content, or pet information to train external AI models without your explicit opt-in consent.


6. How We Share Information

We share information only as described below. We do not sell personal information for money. We do not "share" personal information for cross-context behavioral advertising as defined by the CCPA.

6.1 With other users

Your profile (photos, first name, age, gender, city, bio, interests, lifestyle attributes, prompts, pet information — including the optional answers about each pet and any animals it reacts badly to — parenting style, Daily Rhythm answers, and personality traits) — together with the compatibility percentage, the "Why You Match" highlights, and a summary of how your pets and the viewer's pets might get along, all computed between you and the viewer — is visible to other users of the Service whose preferences you fit and who fit yours. Other users see only the city you entered and an approximate distance — never coordinates. Two free controls in Settings → Privacy change what is shown: Show Distance stops your distance being sent to other users at all, and Show Activity Status stops them being told when you were last active. Both are on unless you turn them off, and neither changes who you appear to — you still show up in the same searches and the same decks. Your phone number, date of birth, and any linked Apple or Google account details are never shown to other users.

Your pets also appear in the Pet Feed. The Pets tab includes a feed of other people's animals, and your pets appear in other people's feeds. A card shows one of your pets and its photos next to your first name, your city, and your first profile photo, and tapping it opens your profile. The feed is not filtered by anyone's dating preferences, so people who would not see you in their deck can still see your pets there. It leaves out anyone you have blocked, anyone who has blocked you, and anyone browsing incognito. There is no liking or commenting on it.

Incognito browsing (Premium). Settings → Privacy → Incognito Mode stops you appearing in other people's decks, in the Pet Feed, and in anyone's Liked You list — your likes and super likes are still recorded, they simply do not announce themselves. One exception keeps matching working: anyone you have already liked or super liked still sees you in their deck, so they can like you back and match. Incognito affects discovery only; it does not hide you from people you have already matched or messaged, and it does not change anything that happened before you turned it on. It applies only while your Premium subscription is active — if it lapses with the setting still on, you appear normally again until it resumes.

Travel mode (Premium). Settings → Discovery → Travel Mode lets you enter a second city you are travelling to. Your deck is then built around that city and your distance filter applies from there. To people in that city you are shown as visiting it, and no distance is shown for you at all — we will not imply you live somewhere you do not. Your home city is what your profile continues to display, and it is never overwritten. Like incognito, it applies only while your Premium subscription is active.

6.2 With service providers

We share information with vendors who process data on our behalf under contract, including:

  • Amazon Web Services (AWS) — database hosting (Postgres on AWS RDS), private photo storage (S3) delivered through a content delivery network (CloudFront), application compute, and caching.
  • Twilio — delivery of one-time sign-in codes by text message.
  • Amazon Rekognition (AWS) — automated screening of uploaded photos for content that violates our Community Guidelines (explicit nudity, sexual activity, graphic violence), and — only if you opt into photo verification — the one-time comparison of your selfie with your profile photos described in Section 4. Rekognition returns labels and a similarity score; it does not retain your photos or selfie.
  • Sentry (Functional Software, Inc.) — crash and error monitoring for the app, our servers, and our website. Sentry receives only the diagnostic reports described in Section 3.2 (stack trace, device model and OS version, app version, the screens and request paths leading up to the error, and your account's internal identifier) — never your name, phone number, photos, messages, or profile content — and keeps them for 90 days.
  • Apple Push Notification service and Google Firebase Cloud Messaging — delivery of the notifications you turn on. They receive your device's push token and the notification text (for example, a match's first name or a short message preview), never the full conversation.
  • Apple App Store / Google Play — payment processing and subscription management.

All vendors are bound by data processing agreements and may only use data for the purposes we instruct.

6.3 For legal reasons

We may disclose information to law enforcement, regulators, or other parties when we believe in good faith that disclosure is necessary to (a) comply with legal process, (b) protect the safety of users or the public, (c) investigate fraud or violations of our Terms, or (d) protect our legal rights.

6.4 In connection with a business transfer

If Lash Digital Solutions LLC is acquired, merges, or transfers assets, your information may be transferred to the successor entity. We will notify you and continue to honor this Privacy Policy unless and until a successor publishes a different policy.

6.5 With your consent

We share information beyond the above scenarios only with your explicit consent.


7. Data Retention and Account Deletion

  • Active accounts: we retain your information for as long as your account is active.
  • When you delete your account (Settings → Delete Account, or by emailing us — see votails.com/delete-account), deletion is immediate:
    • Your photos are removed from storage and from the content delivery network.
    • Your phone number and any linked Apple or Google sign-in methods are removed from the account.
    • All of your matches end, and your profile and messages disappear from every other user's view at the same time.
    • Deletion cannot be undone and the account cannot be reactivated. If you sign in again later with the same phone number, a brand-new account is created.
  • What remains: an anonymized record that contains no name, photos, phone number, messages, or profile content. It exists solely to prevent abuse — for example, so that a ban stays enforceable and promotional programs cannot be gamed by deleting and re-creating accounts. We may also retain information we are required to keep by law or to respond to legal process.
  • Backups: encrypted backups that may contain a copy of your data age out within 30 days of deletion.
  • Messages: retained while the match exists. When either person deletes their account or unmatches, the conversation is no longer visible to the other person.
  • Verification selfies: deleted immediately after the comparison, in every case (see Section 4). The verification result is deleted with your account.
  • Crash and diagnostic reports: kept by Sentry for 90 days from the time of the report, then deleted. Deleting your account does not delete reports already sent, but they contain no personal information beyond your account's internal identifier, which no longer refers to any account after deletion.

8. Your Rights

8.1 All users

Regardless of where you live, you may:

  • Access the personal information we hold about you (request a data export by emailing support@votails.com).
  • Correct inaccurate information (most fields are editable in the app; your date of birth can be corrected by contacting us).
  • Delete your account from Settings → Delete Account, or by emailing us (votails.com/delete-account explains both).
  • Object to certain processing.
  • Withdraw consent at any time (this does not affect prior lawful processing).

When you contact us about your account, identify it by the phone number on the account. We will never ask you for a sign-in code — do not share one with anyone, including us.

8.2 California residents (CCPA/CPRA)

You have the right to:

  • Know what personal information we collect, use, disclose, and retain. The categories we collect are listed in Section 3.
  • Delete personal information, subject to legal exceptions.
  • Correct inaccurate information.
  • Opt out of "sale" or "sharing" — note that we do not sell or share personal information as defined by the CCPA. There is therefore no "Do Not Sell or Share My Personal Information" link required, but you may still contact us to confirm.
  • Limit the use of sensitive personal information — we limit our use of sensitive PI to providing the Service, safety, and compliance, as described in Section 4.
  • Non-discrimination — we will not deny service, charge different prices, or provide a different level of service for exercising your rights.

To exercise these rights, contact support@votails.com. We may verify your identity before responding. We will respond within 45 days (extendable to 90 if needed).

An authorized agent may submit a request on your behalf with written, verifiable authorization.

California Shine the Light: California Civil Code § 1798.83 allows California residents to request information about disclosures of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.

8.3 Other U.S. state residents

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Indiana, Tennessee, New Hampshire, New Jersey, Minnesota, Maryland, Nebraska, and other U.S. states with comprehensive privacy laws have rights similar to the CCPA rights listed above. We honor these rights consistently for all U.S. users.


9. Territorial Scope; International Users

The Service is offered only to U.S. residents, and we process information on servers located in the United States (AWS U.S. regions). We do not target users outside the United States. If you access the Service from outside the U.S., you do so on your own initiative, and your information will be transferred to and processed in the United States.


10. Security

We use commercially reasonable safeguards to protect your information, including:

  • TLS encryption for data in transit
  • Encryption at rest for stored data (AWS RDS encryption)
  • Photos kept in private storage that is not publicly browsable, and delivered to the app through a content delivery network
  • Passwordless authentication — accounts are secured by phone-number verification plus optional Sign in with Apple / Google Sign-In, so there is no Votails password that could be lost or stolen
  • Access controls limiting who can reach production systems
  • Regular security review and dependency updates

No method of transmission or storage is 100% secure. If we become aware of a data breach affecting your information, we will notify you and applicable regulators as required by U.S. state breach-notification laws.


11. Children's Privacy

The Service is strictly for users 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn we have collected information from someone under 18, we will delete it and terminate the account. To report a suspected minor, contact support@votails.com.

In compliance with the U.S. Children's Online Privacy Protection Act (COPPA), we do not target the Service to children under 13 and do not knowingly collect information from children under 13.


12. Cookies and Tracking Technologies

The Votails mobile app uses on-device storage (UserDefaults / DataStore) to remember preferences and session state. The app contains no advertising trackers and no analytics SDKs, never uses the advertising identifier (IDFA / Android Advertising ID), and does not ask for App Tracking Transparency permission. Its only third-party diagnostic component is the Sentry crash-reporting library described in Section 3.2, which is not used for tracking, advertising, or profiling.

Our website, votails.com, does not set cookies. It uses the same Sentry error monitoring to report unexpected page errors (browser type and version, page path, and the technical error — never an IP address or anything you typed); that reporting sets no cookies and uses no browser storage. See the separate Cookie Policy for details.


13. Do Not Track

Some browsers transmit "Do Not Track" ("DNT") signals. There is no consistent industry standard for DNT, so we do not currently respond to DNT signals. We do, however, respect the Global Privacy Control (GPC) signal where applicable to opt you out of sales/sharing (we do not sell or share data regardless).


14. Third-Party Links

The Service may contain links to third-party websites or services (for example, Apple's and Google's subscription management pages, or the safety resources listed in our Safety Policy). We are not responsible for the privacy practices of those third parties. Review their privacy policies before sharing information.


15. Notice to Nevada Residents

Nevada residents may opt out of the future sale of their personal information by emailing support@votails.com with the subject "Nevada Opt-Out." We do not currently sell personal information.


16. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by in-app notice and by posting the updated policy on votails.com at least 30 days before the change takes effect. The "Last Updated" date at the top reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance.


17. Contact Us

For privacy questions, data subject requests, or to report a concern:

Lash Digital Solutions LLC
Attn: Jay Lash, Privacy
330 3rd St S Unit 1516
St. Petersburg, FL 33701
United States
support@votails.com

We will respond within 30 days, or as required by applicable law.