Privacy

Wanting To is built around one idea: what you share about your intimate life belongs to you. This page is the whole picture: what we hold, how it's protected, who can see it, and where the limits are.

Everything personal is encrypted. Your journal is sealed even from us.

What "encrypted" means here

Every personal thing you write (your Preferences, Mood, messages, Experiences, Partner Agreements, notes, bio and photos) is scrambled before it is written down, each with a key belonging to you (or to the conversation it's part of). If someone walked off with the server's disk, a copy of the database or a backup file, what they would have is meaningless noise.

The honest limit: the running app can unscramble your data, because it has to show you your own matches and messages. So this protects your data at rest (disks, backups, database files, stray copies), not against someone who takes control of the live server itself. Making even that impossible would mean only you could ever read your data, which would also mean losing it all if you forgot your password, and no matching at all. We think this is the right trade; you should know we made it.

Your Intimacy Journal and Experience Reflections go further still: they live in a separate encrypted database that the analytics and administration code physically cannot open: not a policy, a structural rule the build enforces.

Everything we hold, and how it's protected

Identity/account

The minimum needed to run and secure your account. No real name, no street address, no city.

WhatProtectionWhy
Email address Stored as text Used to find your account when you log in and to send you mail.
Password (hashed, never stored as typed) & 2FA secret Hashed A password hash can be checked but not reversed.
Username Stored as text Anonymous by design. It is never your real name.
Plan, verification & moderation state Stored as text Needed to run the service and enforce the age gate.
Card and billing details Never stored You pay on Stripe's own checkout page; we keep only a Stripe customer and subscription reference.
Login history & security log Stored as text Kept 90 days; IP addresses are scrubbed from older entries.
How you heard about us & any referral code Stored as text Optional at sign-up; counted to see which channels work. Never about your intimate life.
Which Terms version you agreed to, and when Stored as text A record we need in case a question about the agreement ever comes up. Deleted with your account.
Waitlist email address Stored as text Only until your invitation is used, then it is deleted.
Privacy request log Hashed Records that an export or deletion was done, by a one-way fingerprint of the email, never the address itself.
Installed-app push subscriptions Stored as text A device address supplied by your browser, needed to deliver a push.

Intimate/private

Everything about your intimate life. All of it encrypted, none of it ever sold or shown as individual records.

WhatProtectionWhy
Gender, orientation, birthday, ZIP, bio Encrypted Encrypted with your own key.
Mood Encrypted Encrypted with your own key.
Preference selections (comfort, side, intensity) Encrypted Even which Preferences you looked at is unreadable. The whole list is one sealed value.
Messages & group chats Encrypted Encrypted with a key for that conversation.
Experiences (proposals, answers, boundaries) Encrypted Encrypted with a key for that Experience.
Partner Agreements & their notes Encrypted Encrypted with a key for that connection.
Notifications you have been sent Encrypted Encrypted with your own key.
Journal photos Encrypted A link alone is never enough to open one. Messages are text-only and profile pictures are stock avatars, so no other photos are stored.
Support tickets & replies Encrypted Encrypted; readable by the admins handling your ticket.
Reports you make about another member Encrypted Encrypted like any ticket. Contains only the messages you chose to share; the other person is never told who reported them.
Intimacy Journal entries Encrypted Separate database the analytics and admin code cannot open at all.
Experience Reflections Encrypted Same separate database; only a "done" marker lives in the main one.

Aggregated insights

Counts across large-enough groups, from members who opted in. Never stored against a person.

WhatProtectionWhy
Opted-in demographic & interest statistics (groups of 5+) Never stored Computed on the fly from opted-in members only.

Photos

Messages and group chats are text only. Wanting To doesn't send photos between members at all, so there are no intimate images passing through the app to leak, forward or screenshot out of context. Profile pictures are chosen from a set of Wanting To avatars rather than uploaded, so there is no photo of your face in the app. The only photo you can add is an optional one on a journal entry: it's encrypted as a file, it's yours alone, and the only way to see it is through the app, which checks who is asking first. Having the link is never enough.

Payments

Premium is paid through Stripe, on Stripe's own secure checkout page. Your card number never reaches Wanting To. We can't see it and don't store it. What we keep is a reference to your Stripe customer and subscription, so we know your plan is active. Stripe keeps the payment records that tax and card-network rules require, under its own privacy policy. Charges appear on your statement as WHATBOXLABS, never "Wanting To". Receipts go to the email on your account. Details are in the Subscription & Refund Policy.

Who else handles data for us

A few service providers help run Wanting To, each under contract and only for that job: Render hosts the app and its encrypted database; Resend delivers our emails (which never contain anything personal; see below); and Stripe processes payments. None of them receives your Preferences, matches, messages or journal in readable form. We never sell data, and there is no advertising or tracking code in the app.

What your partners see

Administrators never see your Preferences. Each partner sees your matches and anything you've locked to "Always show" on your profile, with how much you want each one (Curious to Favorite). Beyond that, they see only what you've chosen to show that specific partner: your full list (including your reds, which simply mean "not for me") and your Mood. You set this per partner when you connect and can change it any time on their Partner page. Partner Agreement answers, including any note you write, are shown to that partner, since agreeing on expectations is the point of them. The same goes for a note you leave on a Preference: it's written for your partner, encrypted, and shown only to the two of you.

Your partners are told that something changed (you updated your Preferences, saved Agreements, want to discuss a match, ended the connection), but never what changed.

If you report someone

You can report a problem with anyone you're connected to or share a group chat with. Because your messages are encrypted and our team can't read them, you choose which of that person's messages to share as part of the report. Only those are visible to the administrators handling it, and nothing else from your conversations. The report is stored encrypted, and the other person is never told who reported them.

What we put in emails

Emails from Wanting To never contain your Preferences, your matches, your messages, or anything from your journal. They say only that something is waiting for you in the app. Email itself isn't a private medium, so we keep it empty of anything that matters.

What administrators can see

Administrators run the platform, so they can see account-level things: your username, email address, plan, whether an account is suspended or banned, support tickets you submitted, and a security log of actions. They cannot see your Preferences, matches, Mood, messages, Experiences, Partner Agreements, photos, journal or reflections. Nothing in the admin panel decrypts those, and the statistics administrators see are the opted-in, grouped counts below.

Research is opt-in

By default, you are not included in any statistics. If you choose "Yes, contribute anonymous statistics" on your profile, your answers can be counted in aggregate: only ever in groups of 5 or more, so no one can be singled out, and never your individual profile, partner connections, journal entries, Experience reflections, messages or identifying information. Those counts are worked out in memory from values that arrive with no member attached. You can change your mind any time.

How long we keep it

Your data stays while your account exists. Login history is deleted after 90 days, and IP addresses are scrubbed from older security-log entries automatically. Records of which emails we sent (never their content) are kept 30 days. A waitlist email address is deleted once its invitation is used. The app also keeps encrypted backups of its databases for about 7 days, in case something needs to be restored. Anything you delete is gone from those backups within that time.

If you delete your account, everything that is only yours is erased: profile, Preferences, Experiences, Agreements, journal, reflections, photos, notifications and tickets. Messages you sent to a partner are the one exception: they sit in a shared conversation, so the message stays in their thread with your content scrubbed and shown as "[deleted account]". If you paid for Premium, your subscription is stopped and your Stripe customer record is deleted; Stripe keeps only the payment records the law requires. We keep a note that a deletion was done (identified only by a one-way fingerprint of your email address, never the address itself) so we can confirm it if you ever ask.

Your data, your call

You can download everything tied to your account (decrypted, for you alone) or permanently delete it, from your profile page. Deletion is immediate and cannot be undone.

Last reviewed: 2026-09-25 (build 1.0.3).