Privacy Policy
Last updated: 10 May 2026
This Privacy Policy describes how SweetArt ("we", "us", "our") collects, uses, and shares your information when you use the SweetArt mobile application and any related services (collectively, the "Service"). SweetArt is operated by Venües (the "Company"), based in Türkiye.
By creating an account or using the Service, you confirm that you have read and understood this Privacy Policy.
1. Who can use SweetArt
SweetArt is for adults aged 18 and older. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete that data immediately. If you believe a minor is using SweetArt, please report the account from inside the app or contact us at the address below.
2. Information we collect
Information you provide directly
- Account: email address and password (passwords are stored in salted/hashed form by our auth provider; we never see your raw password).
- Profile: name, age, height, job, location (country and city), bio, art forms, art movements, originality preference, looking-for modes, photos, prompts.
- Aesthetic quiz: your forced-choice picks and the resulting aesthetic vector and label.
- Briefs (Creating mode): the briefs you publish and applications you submit.
- Messages: the text content of chats with matches and brief groups.
- Reports and blocks: when you report or block another user, we record the action and any reason or description you provide.
Information we collect automatically
- Device and app information: app version, OS version, device model, language, time zone.
- Usage data: which screens you open, when you swipe / match / message, and similar interaction events used to debug and improve the Service.
- Approximate location based on the city you select (we do not currently use GPS).
- Diagnostic data: crash logs, error reports.
Information we do not collect
We do not collect precise GPS location, contacts, microphone, calendar, health data, or financial account numbers. Photos are processed in the app and uploaded to our storage; we do not access your camera roll beyond the file you choose.
3. How we use your information
We use the information we collect to:
- Operate, maintain, and provide the Service (show profiles, run matching, deliver messages, host briefs).
- Run automated photo moderation to keep the community safe (see Section 5).
- Personalize matching and the aesthetic-aware experience.
- Communicate with you about the Service (support, security, important changes).
- Detect, investigate, and prevent fraud, abuse, harassment, and other harmful activity.
- Comply with legal obligations and respond to lawful requests.
We do not use your information to serve third-party advertising, and we do not sell your personal data.
4. Legal bases (EU/UK users — GDPR)
Where GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service you signed up for.
- Legitimate interests — to improve the Service, ensure safety, prevent abuse.
- Consent — when required (e.g. age confirmation at sign-up).
- Legal obligation — to comply with applicable laws.
You may withdraw consent at any time by deleting your account in Settings.
5. Photo moderation and AI
When you upload a photo, the photo is sent to Amazon Web Services Rekognition for automated moderation. Rekognition returns labels indicating whether the image contains explicit, violent, or otherwise inappropriate content. We use those labels (combined with art-aware logic) to decide whether to publish the photo. The image data passes through AWS in transit; AWS does not retain it for training. See AWS Rekognition's documentation for their handling.
6. Sharing your information
We share information only as described below:
- Service providers that help us run SweetArt, under contracts that limit how they may use the data:
- Supabase — database, authentication, storage, real-time, and edge functions.
- Amazon Web Services (AWS) — photo moderation via Rekognition.
- Apple and Google — distribution and subscription processing through their respective app stores (when applicable).
- Other SweetArt users — the profile information and content you choose to share are visible to other users of the Service (your matches see your messages; brief applicants see the brief; etc.).
- Legal and safety — we may disclose information if required by law, valid legal process, or to protect the safety of users or the public.
- Business transfers — if SweetArt is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change.
We do not sell your personal data to third parties.
7. International data transfers
Supabase and AWS may host data in regions outside Türkiye, including the European Union and the United States. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for international transfers.
8. Data retention
We retain your account data for as long as your account is active. When you delete your account from Settings, we permanently delete your profile, photos, messages, briefs, swipes, matches, blocks, and reports. Some logs and backups may persist for up to 30 days for security and legal purposes before being purged.
9. Your rights
Depending on where you live, you have rights regarding your personal data:
Türkiye (KVKK) — You may request to learn whether your data is being processed, request information about how it is processed, request correction of incomplete or inaccurate data, request deletion or anonymization, request restriction of processing, and object to certain processing.
EU/EEA/UK (GDPR) — Access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority.
California (CCPA/CPRA) — Right to know, delete, correct, and opt out of "sales" (we do not sell). California residents may also designate an authorized agent.
To exercise any of these rights, write to us at the address below or use the in-app Settings → Delete account flow.
10. Security
We use HTTPS for all data in transit, encryption at rest for the database, and salted/hashed password storage. Photos are stored in a public-read storage bucket because they are intended to be visible to other users; we do not use signed URLs for profile photos. We restrict employee access to production data on a need-to-know basis.
No system is 100% secure. If we experience a data breach that materially affects you, we will notify you in line with applicable law.
11. Children's data
SweetArt is for users 18 and older. We do not knowingly collect data from anyone under 18.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you (in-app or by email) and update the "Last updated" date above. Continued use of the Service after changes take effect means you accept the updated policy.
13. Contact us
For privacy questions or requests, contact:
- Email: privacy@datencreate.com
- Company: Venües, Türkiye
We respond to verifiable requests within 30 days.