A product privacy architecture built around data minimization, user control, purpose limits, sensitive-data caution, and explicit boundaries on race inference.
The current public-data site has no account system, ad tracker, photo upload, or member database. Device-local features are labeled.
01
Core promises
Ask for less
The product should not collect identity, financial, health, relationship, location, or photo data merely because it might be useful later.
Purpose before collection
Shortest practical retention
Export and deletion
No sale of personal information
02
No race inference
Identity belongs to the person
Photo and personalization tools must never secretly classify a person’s race. Users choose the characteristics relevant to their request.
Self-described needs
No biometric identification
No hidden attribute prediction
Human-readable controls
Authenticity contract
Structure can be complete before claims are real.
Where genuine evidence exists, the site publishes it with source, vintage, identifier, and limitation. Where a marketplace, review, recommendation, partnership, price, benefit, event, or score lacks real-world support, the interface remains a clearly labeled example.