Skip to content

Mutually

Privacy Policy

Last updated 29 September 2026 · Version privacy-2026-09-29-draft

Draft — pending legal review. This page describes how Mutually works today. It isn’t final, and it isn’t yet a binding document.

This is a working draft written by the Mutually team to describe, as accurately as we can, how the product handles information today. It has not yet been reviewed by counsel and it is not yet a binding policy. The reviewed version will replace it, with a new version number, before we open the waitlist or invite members at scale.

Who we are

Mutually is a private, invite-only network for thoughtful romantic introductions. In this policy, "Mutually", "we" and "us" mean the company that runs Mutually and decides how your information is used (the "controller").

  • Post: Mutually, 521 5th Avenue, 17th Floor, #9037, New York, NY 10175, USA
  • Email: support@mutually.lol (privacy questions and requests)

Who this policy covers

  • Visitors to mutually.lol, including people who join the waitlist.
  • Members — people who are introduced (we call them Seekers) and people who help describe them (Connectors) who have signed in.
  • People invited to describe a friend who haven’t created an account. A friend gave us your name and email address or mobile number so we could send you a private link.

What we collect, and why

If you join the waitlist

  • Your email address — to confirm it’s yours (we send one confirmation email) and to write to you when there’s room.
  • Where you’re based (optional, free text) and your time zone (read from your browser) — so we write at a sensible hour. This never affects whether or when you’re invited.
  • Which version of this policy you saw, and a one-way fingerprint of your IP address — to keep a record of consent and to stop abuse.

If someone invites you to describe them

  • Your name or nickname and your email address or mobile number, as your friend entered them — to send you the private link and one reminder.
  • What you choose to write or record about your friend, how you know them, and who may see each answer (see "Who can see what").
  • Your confirmation that you’re 18 or over, and a one-time code we send to confirm the link reached the right person.

You don’t need an account to answer. If you’d rather not be asked again, every invitation has a link to stop all invitations to your address.

If you become a member

  • Account and contact details: your phone number and email address (to sign in and to verify you), your name, and your date of birth (to confirm you’re 18 or over).
  • Verification: a selfie, compared with your profile photos to confirm the photos are really you. See "Photo and selfie checks" below.
  • Profile: your photos, the facts you choose to add, and your preferences — including what you’re looking for, where you’d happily live, and whether you’d consider someone elsewhere.
  • The conversation: what you tell our interviewer, typed or spoken. Spoken answers are turned into text. From the conversation we draft notes about you; nothing we infer is used to find introductions until you’ve confirmed it.
  • Your circle: the people you invite to describe you, and what they choose to share.
  • Introductions: the introductions you’re part of, your private decisions, messages, plans to meet, and your answers to the short private questions afterwards.
  • Safety: reports you make or that are made about you, blocks, and the decisions our Trust & Safety team takes.
  • Technical records: sign-in times, device and browser type, and a device identifier, so we can keep your account secure and warn you about a sign-in from a new device.

Sensitive information

Some information you might share — your faith, health or sexual orientation — is especially sensitive. We only use it with your explicit consent, only to find introductions, and you can delete it on its own at any time without deleting anything else. Your selfie check may involve biometric processing, which we also do only with your explicit consent (see below).

How we use information

  • To run Mutually: to create and secure your account, to verify you, to build your profile with you, to send your circle their links, and to deliver messages and notifications you’ve asked for.
  • To find introductions: our systems look for possible introductions only among people your circles know. A person who knows you both decides whether an introduction is made, and each of you decides privately whether to go ahead. AI suggests; it never decides.
  • To keep people safe: to review reports, enforce our Community Standards, prevent fraud and abuse (including bot protection on our forms), and keep records of safety decisions.
  • To improve Mutually: to understand which pages and features help, using aggregated product analytics — on the website only if you allow the analytics cookie.
  • To meet legal obligations: to respond to lawful requests and keep the records the law requires.

We don’t sell personal information, we don’t share it for cross-context behavioural advertising, and we don’t show ads.

  • Contract — to provide the service you’ve asked for (your account, your circle, introductions, messages).
  • Explicit consent — for sensitive information (faith, health, orientation), for the biometric part of the selfie check, and for analytics cookies. You can withdraw consent at any time; it doesn’t affect what happened before.
  • Legitimate interests — to keep Mutually secure, prevent abuse, protect members' safety, and understand how the service is used, balanced against your rights.
  • Legal obligation — where the law requires us to keep or disclose information.

For a friend who describes a Seeker, we rely on legitimate interests to send you the first invitation (your friend asked us to), and on your choices from then on.

AI and automated processing

  • We use AI models to hold the onboarding conversation, turn speech into text, draft notes and summaries for you to confirm, suggest questions, and notice possible introductions.
  • AI never makes an introduction on its own and never decides whether you meet someone: a Connector who knows you both chooses whether to make an introduction, and you choose whether to go ahead.
  • We don’t give people scores, ratings or rankings, and we don’t use attractiveness signals.
  • Our AI providers process information only to provide their service to us, and we send them only what each task needs.
  • You can ask for a person to review any automated step that affects you, such as an automated selfie check.

Photo and selfie checks

  • Every photo you upload is checked before anyone else can see it — for safety (for example, nudity or violence) and to confirm it shows you. Photos are re-encoded to remove hidden metadata such as location.
  • Your verification selfie is compared with your profile photos to confirm they show the same person. This check is run automatically by our verification provider or, where the automated check isn’t confident, by a member of our Trust & Safety team.
  • We keep the outcome and the similarity score. The selfie image itself is deleted 30 days after the decision.

Who can see what

  • Your photos are only ever seen inside an introduction — never in a list, search or feed. Our Trust & Safety team can see them only to check they’re really you and that they follow our standards.
  • That you’re on Mutually: only people you invite into your circle, and people you’re introduced to.
  • What your circle wrote: each person who describes you chooses, for each answer, whether it’s used only privately by Mutually to find introductions, shared in paraphrase, shared with their name, or shown on your profile. You see what each person allows.
  • Your yes or no to an introduction is never shown to anyone unless you both say yes. A no is never reported back to the other person.
  • Your debrief answers are private to you and to Mutually.
  • Nobody can browse or search the network — not members, not Connectors.

Service providers

We use a small number of providers who process information on our instructions, under written agreements, and only to provide their service to us:

  • Railway — application hosting, database and cache, in the European Union (Netherlands).
  • Cloudflare — file storage for photos, voice notes, selfies and data exports (R2, Western Europe), and bot protection on our forms (Turnstile).
  • Resend — sending and receiving email (European Union, Ireland).
  • Twilio — phone number verification codes and text messages (United States and global carrier networks).
  • Anthropic — AI models for the conversation, notes and suggestions (United States).
  • Voyage AI — turning text into numerical representations used to find possible introductions (United States).
  • Deepgram — turning spoken answers and voice notes into text (United States).
  • Amazon Web Services (Rekognition) — automated photo safety and selfie checks (European Union, Ireland).
  • Sentry — error monitoring, configured not to collect personal information (European Union, Germany).
  • PostHog — product analytics, only with your consent on the website, with IP addresses discarded and no session recording (European Union).

We may also share information when the law requires it, to protect someone’s safety, or as part of a merger or sale of the business (in which case this policy would continue to apply to your information).

International transfers

Our main hosting, database and file storage are in the European Union. Some providers above are based in, or process information in, the United States. Where information leaves the EU, UK or Switzerland, we rely on the European Commission’s standard contractual clauses (and the UK and Swiss equivalents) or another lawful transfer mechanism.

How long we keep things

  • Unconfirmed waitlist entries: deleted after 30 days. If you become a member, your waitlist entry is deleted 30 days later.
  • If you leave the waitlist: your entry is deleted immediately. We keep only a one-way fingerprint of your address so we never email it again.
  • Invitations to describe a friend: a link lasts 30 days; unfinished answers are kept for 60 days so you can come back to them, then deleted.
  • Selfie images: deleted 30 days after the verification decision.
  • Data exports you request: available for 7 days, then deleted.
  • Email and text-message delivery records: 90 days. In-app notifications: 90 days.
  • Messages in a closed conversation: kept while both accounts exist, so either of you can look back. We’re introducing automatic deletion 12 months after a conversation closes.
  • Your account: when you delete it, it’s scheduled for deletion and can be restored for 30 days. After that, your profile, photos, conversation, what your circle wrote about you, introductions and messages are permanently deleted.
  • Safety records: reports and the decisions taken on them may be kept longer where needed to protect people, handle an appeal, or meet a legal obligation ("legal hold"). Security and audit records are kept with your identity removed.
  • Blocked addresses: if an account is removed for serious harm, we keep a one-way fingerprint of its phone number and email address so it can’t simply sign up again.

Security

  • Information is encrypted in transit and at rest. The most sensitive fields — such as contact details, what you say in the conversation and what your circle writes — are additionally encrypted field by field, and looked up by one-way fingerprints rather than in plain text.
  • Access by our team is limited to people who need it, protected by two-factor authentication, and logged.
  • We never put personal information in logs, error reports or analytics.

No system is completely secure, but we work hard to protect what you share, and we’ll tell you and the relevant authorities promptly if a breach puts you at risk.

Your choices and rights

From Settings, or by writing to support@mutually.lol, you can:

  • see and download your information (Settings › Account › Download your data);
  • correct anything that’s wrong, including notes drafted from your conversation;
  • delete a single sensitive answer, a photo, your circle’s contributions, or your whole account;
  • withdraw consent for sensitive information, biometric checks or analytics;
  • object to or ask us to restrict some uses, and ask for a person to review an automated decision;
  • pause introductions at any time.

Depending on where you live, you may have further rights (for example under the GDPR, UK GDPR or US state privacy laws), including the right to complain to your local data protection authority. We’ll answer requests within one month, and we won’t treat you differently for using your rights. If you’re a Connector without an account, write to us from the address or number your link was sent to.

Children

Mutually is for adults. You must be 18 or over to join the waitlist, become a member, or describe a friend. If we learn that someone under 18 has given us information, we delete it.

Cookies

We use strictly necessary cookies to keep you signed in and to protect forms. We use one analytics cookie on the website only if you allow it. See the Cookie Policy.

Changes

When this policy changes in a meaningful way, we’ll give it a new version number, and tell members in the app and by email before the change takes effect. The version you accepted is kept with your account.

Contact

Questions, requests or complaints: support@mutually.lol, or write to Mutually, 521 5th Avenue, 17th Floor, #9037, New York, NY 10175, USA.

We’d rather introduce you well than introduce you often.

Mutually is invite-only while the network grows, one circle at a time.

The list isn’t open yet.

We’re inviting a few people at a time. If someone invited you, open the link in their message.

Already a member? Sign in