The fine print · Privacy
Privacy Policy
This covers the Booked app and this website. It was written by the person who wrote the code, from the actual database columns — not adapted from another company’s template. If a sentence here is wrong, it’s a bug, and we want to hear about it.
Last updated August 1, 2026
Where we are right now
Booked is not open yet. Today this website does one thing: it takes an email address and holds it until we open in Houston. There is no app in the store, no accounts, no profiles, no matches.
So most of this policy describes something that hasn’t started. We’re publishing it early anyway, for two reasons: you should be able to read what you’re signing up for before you sign up for it, and writing it now forces us to build the app to match. The sections below are marked waitlist or app so you always know which parts are live.
Who we are
Booked is built and operated by ABH Federal LLC, a Texas limited liability company owned by Andrew Lopez. We’re the ones responsible for your data — the legal word is “controller,” and it means the buck stops with us, not with a vendor.
Questions, requests, complaints: privacy@booked.date. A person reads it, and that person is currently the founder.
The waitlist, in full
Waitlist. When you type your email into the box on this site, we write one row to a database. The complete row: your email address, a short source tag (like “landing”) saying which page it came from, a city (it says Houston for everyone — we do not look up or infer where you actually are), any campaign or referral tags that were on the link you clicked, whether you’ve been emailed yet, and a timestamp.
No name, no phone, no age, no gender, no location, no photo. We don’t need them to send one email.
We use it to email you when Booked opens in Houston, plus at most one short note if something big changes before then. Every email has one-click unsubscribe. We also count how many people signed up, because that number is what convinces a Houston restaurant to talk to us. It’s a count, not you.
What the app collects — things you type in
App. Booked is a dating app that ends in a real reservation at a real place, which means it needs more than most apps and less than you’d fear. Here is the whole list.
- Your phone number. It’s how you sign in — we text you a code instead of asking you to invent another password. Other users never see it.
- Your first name and birthday. The name goes on your profile. The birthday is how we enforce 18+ and show your age; we store the date, not just the age, so the number stays right on your birthday.
- Your gender, and who you want to meet. Required — a dating app can’t match without it.
- Your photos. The ones you pick from your camera roll. You choose each one; we never reach into your library on our own.
- Your bio, your “ideal date” answer, and your interview answers. Free text you wrote.
- A voice memo, if you record one. Optional. It plays on your profile. Delete it any time and the audio file goes with it.
- What you’re looking for, what kinds of dates you like, and what you’re comfortable spending. This is what makes the app suggest a wine bar instead of a $200 tasting menu.
- Your ethnicity, and whether you smoke, drink, or use drugs — plus your preferences on those in other people. All optional, all skippable, and skipping costs you nothing but a slightly blunter deck. See the section on sensitive information below, because these deserve their own paragraph.
- An emergency contact, if you add one. A name and a phone number. This one isn’t about you — read the next section.
Your emergency contact is someone else’s data
App. If you add an emergency contact, you’re handing us a name and phone number belonging to a person who never opened our app. We take that seriously, and we’d rather say the awkward part out loud: ask them first.
We use it for exactly one thing — if you press the safety button during a date, we can help you reach them. We do not text them, market to them, add them to any list, look them up, or use their number to find them on Booked. It sits encrypted next to your profile until you delete it or delete your account, and no other user can see it.
What the app collects — things you do
- Who you book, pass on, and bookmark. Every swipe decision, both directions.
- Your messages. Message text is stored so the conversation still exists when you close the app. It is not end-to-end encrypted — we can read it, and we will if it’s reported to us. Anyone who tells you a dating app can moderate harassment without being able to read messages is selling something.
- Games you play in chat, and what you scored.
- Your bookings. Venue, date, time, party size, any special request you typed, and afterwards whether the date happened.
- Your check-in. See the location section.
- Community posts and venue ratings you publish. These are public inside the app by design.
- Reports you file, blocks you make, and your answer to “did you feel safe?”
- Points earned and spent, and — when the paid tier exists — what you bought and when it renews.
Location: coarse to match, precise only at the table
App. Booked asks for location twice, and the difference between the two matters.
- Once at setup, to know which city you’re in. This is what stops us showing you a perfect match in Dallas.
- Once at the venue, when you check in. That one is precise. We compare where you are to where the restaurant is, store the coordinates and the distance, and that comparison is what turns a booking into a real date and pays out your points. It happens when you tap check in, and not otherwise.
We ask for foreground location only — the kind that works while you’re looking at the app. Booked cannot follow you around in the background, because we never requested the permission that would let it. If you press the safety button during a date, we read your location then too, to get help to the right address.
Other users are never shown your coordinates. They see a city and a distance, rounded.
Verification selfies — and the thing we don’t do
App. Before an at-home date, both people take a selfie in the app. It gets uploaded and held with that booking, and it exists so that if something goes wrong there is a photograph of who was actually there.
We do not run face recognition on it. No faceprint, no face template, no geometry measurements, no matching your selfie against your profile photos or against anyone else’s. Under Texas law that distinction is the whole ballgame — a biometric identifier is a mathematical model of your face, and we don’t create one. If we ever decide we need to, this policy changes first, we tell you, and we ask.
Selfies are never shown on your profile and never shown to anyone you haven’t matched with.
What the app works out about you
App. Booked reads your own answers and turns them into a set of numbers — how direct you are, how quickly you like to meet, how loud a room you enjoy, that sort of thing. Those numbers are what rank your deck, and they’re why the app suggests a specific table at a specific place instead of a generic list.
Three promises about that, because this is where dating apps usually get weird:
- There is no score on you. Booked does not compute a desirability, attractiveness, or quality rating for any person, and it never ranks the whole user base against each other. The numbers describe a pairing — you and one other person — and they get thrown away and recomputed.
- No human at Booked browses your report. It’s generated when you open the app and shown to you.
- It learns from what happened, not from what you look like. When a match leads to a real date, we log that the pairing worked so the ranking gets better. Photos are never an input.
Nothing here decides anything legally significant about you. It decides the order of a deck of cards.
What we collect without asking
- App. A push notification token, so we can tell you that you matched. Turn notifications off and it stops.
- App. Basic device and app-version information, which is what makes a crash report useful.
- Waitlist + app. Ordinary server logs — IP address, browser or device type, what was requested and when. Every host on earth keeps these; they’re what lets us block a bot hammering the signup form. We don’t mine them and we don’t join them to your profile.
- Waitlist. This website runs Vercel Analytics, which counts page views and where visitors came from in aggregate. It sets no cookie and can’t tell us who you are.
The sensitive stuff, named
Some of what a dating app holds is, in plain terms, sensitive: your ethnicity, the fact that who you want to meet reveals your sexual orientation, precise location, whether you drink or smoke or use drugs, and your photographs.
Our rule is the same for all of it. We ask before we collect it, every field is optional except gender and who you want to meet, and we only use it for the thing you gave it to us for. Your ethnicity fills in a profile field and applies your own filters. Your habits do the same. Neither is ever used for advertising, sold, licensed, shared with a data broker, or handed to anyone outside the list of vendors below.
If you filled one in and want it gone, you can clear it in the app yourself. It doesn’t get archived somewhere for our records.
What we don’t do
Most of this list is unremarkable to write and unusual to be able to prove. All of it is verifiable in the app’s dependency list — there is no analytics SDK, no advertising SDK, and no tracking SDK in the build.
- We don’t sell your personal information. Not now, not as a business model we’re holding back.
- We don’t share it for cross-context behavioural advertising. There are no ad pixels in Booked.
- We don’t buy data about you from brokers, and we don’t enrich your profile with it.
- We don’t upload your contacts or read your address book. We never ask for the permission.
- We don’t track your location in the background.
- We don’t run face recognition, and we don’t create biometric identifiers.
- We don’t read your camera roll — you pick each photo.
- We don’t use your photos or messages to train a general-purpose AI model.
- We don’t paywall safety. Blocking, reporting, and the safety button are free forever.
Why we have any of it
Every use falls into one of five buckets:
- To run the thing. Sign you in, show your profile, deliver messages, hold a booking, verify a check-in, pay a venue, award points.
- To match you. Rank your deck and suggest places you’d both actually enjoy.
- To keep people safe. Review reports, act on blocks, catch spam and fake accounts, and enforce the rule that a first date is never at someone’s home.
- To tell you things. Matches, messages, booking reminders. You control push notifications.
- To keep the lights on. Aggregate counts, crash reports, and the tax and accounting records the law requires us to keep.
Who else touches it
The complete list of companies with any access, and the one job each does:
- Supabase — the database, sign-in, and file storage. Your profile, messages, photos and voice memos live here.
- Twilio — sends the sign-in code to your phone. Gets your phone number and nothing else.
- Expo — delivers push notifications. Gets a device token and the notification text.
- Apple and Google — distribute the app and process any in-app purchase. If you buy a subscription, they handle the card; we never see your card number.
- Stripe — processes date payments and pays the venue. Card details go to Stripe directly; we store an amount, a status, and a reference.
- Vercel — hosts this website and runs the analytics described above.
- SendGrid — sends the waitlist email.
- The venue you booked — gets your first name, the date and time, the party size, and any special request you typed. That’s a reservation. They don’t get your phone number, your profile, or who you’re going with.
Each one is a vendor doing a job we asked for, under contract, and none may use your data for their own purposes. If we add a ninth, it gets added here before it goes live.
Two exceptions we won’t pretend don’t exist. If a court, subpoena, or law enforcement request legally compels us, we comply — and we’ll tell you it happened unless we’re legally barred from doing so. And if Booked is ever sold or merged, your data moves with the company, bound by this policy, or you get told first and can leave before it happens.
Safety, and when we act without asking you
If we believe someone is in danger — a credible threat, a report of assault, a minor on the platform — we will share what we have with law enforcement or emergency services without waiting for permission, including message content and location. That is the one place where safety outranks privacy, and we’d rather you know the rule now than discover it later.
When you report someone, a human at Booked reads the relevant messages. When you block someone, they are not told. Reports and blocks are kept even if the other person deletes their account — otherwise deleting and re-registering would erase a record of harm, which is exactly the loophole a bad actor would use.
What other people can see
- Anyone in your deck: your first name, age, photos, bio, prompt answers, voice memo, city, an approximate distance, and the profile details you filled in.
- People you’ve matched with: the above, plus your messages and anything you both do in a shared game or a booking.
- Everyone in the app: community posts and venue ratings you publish, under your name.
- Nobody, ever: your phone number, your birthday as a date, your exact coordinates, your emergency contact, your verification selfie, your payment details, who you passed on, and the people who liked you but you haven’t seen yet.
How long we keep it
- Your account: while it exists. Delete it and the profile, photos, voice memo, preferences and messages go within 30 days — usually the same week.
- Waitlist email: until you use the invitation, until you ask us to drop it, or twelve months after we open in Houston — whichever comes first. If we never launch, we delete the list and say so.
- Verification selfies: 90 days after the date, then deleted. Longer only if that specific booking is under an open safety report.
- Check-in coordinates: kept with the booking record, because it’s the proof the date happened and the points were earned.
- Safety reports, blocks, and any account we removed: kept indefinitely. This is the one thing that survives deletion, and it survives it on purpose.
- Payment and commission records: seven years, because tax law says so.
- Server logs: a matter of weeks, then they roll off.
Deleting your account
It’s in the app, in settings, and it is one screen — not a retention flow, not five “are you sure” panels, not an email to support that goes unanswered for a week. We built the exit before we built the paywall.
When you delete: your profile disappears from everyone’s deck immediately; your photos, voice memo, messages and preferences are erased within 30 days; your matches see the conversation end. What stays is listed above — safety records and the financial records we’re required to hold.
You don’t have to delete everything to fix one thing. Any single field — a photo, your voice memo, your ethnicity, your emergency contact — can be cleared on its own, in the app, without asking us.
Your rights
Depending on where you live, the law gives you formal rights over data like this — to see it, correct it, delete it, take a copy elsewhere, opt out of it being sold or used for targeted advertising (we do neither), and to not be discriminated against for asking.
We are not going to make you prove you qualify. Email privacy@booked.date and ask, and we’ll do it — whoever you are, wherever you’re writing from. We’ll answer within 45 days and normally much faster. If we ever say no to a request, we’ll say why, and you can write back and argue; a person will actually reconsider it.
For a deletion or copy request we’ll confirm you control the account — usually by texting the number on it — because handing someone’s dating profile to a stranger who emailed us would be its own privacy violation.
You have to be 18
Booked is for adults. You must be 18 or older to join the waitlist or use the app. We ask for a birthday at signup and block anyone under 18 from finishing setup.
We don’t knowingly collect anything from anyone under 18. If we learn an account or an email belongs to a minor, we delete it. If you’re a parent and you think your kid signed up, email privacy@booked.date and it’s handled the same day.
How it’s kept
Data lives in a Postgres database at Supabase with row-level security switched on, meaning the rules about who can read what are enforced by the database itself rather than by the app politely asking. Traffic is encrypted in transit; your sign-in session is held in the phone’s secure keystore, not in ordinary app storage. Photos, voice memos and selfies sit in access-controlled storage, not on a public URL.
No system is perfect and we’re not going to claim ours is. If we ever have a breach that puts you at risk, we will tell you what happened, what was taken, and what we did — quickly, in plain English, and without a press release that buries it.
Where this happens
Booked is operated from Texas and every vendor above is a US company; your data is stored and processed in the United States. If you’re writing from outside the US, that’s where it goes.
This policy is governed by the laws of the State of Texas. Any dispute about it belongs in the state or federal courts sitting in Harris County, Texas.
If this page changes
We’ll change the date at the top. If a change actually matters — meaning we’d start doing something with your data that this version doesn’t permit — we’ll tell you in the app and by email before it takes effect, and where the law requires consent, we’ll ask for it rather than assume it from your silence.
Old versions stay available on request. We’re not going to quietly rewrite history.
Ask us anything
privacy@booked.date. A person reads it. If something on this page isn’t true, or isn’t clear, we want to know — that’s the entire point of the company.