Privacy Policy
Last Updated: March 17, 2026
WhoDat Ventures, Inc. ("WhoDat," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy outlines our principles, technical safeguards, and operational practices regarding how we collect, process, use, disclose, and protect information when you access or use our mobile applications, web applications, profiles, websites, APIs, and associated digital services (collectively, the "Services").
- Visual Search Photos are Ephemeral: Photos submitted to perform visual searches are processed in-memory in real time to return search results. We do not store, retain, or sell your visual search photos, nor do we use them to train proprietary AI recognition models.
- No End-User Biometric Identification: We do not capture, record, enroll, or sell biometric identifiers or facial geometry templates of our end-users.
- No Precise Location Tracking: We do not track or record your device's continuous GPS hardware coordinates. Event recommendations are based on coarse IP geolocation or venue locations.
Please read this Privacy Policy carefully. By accessing or using the Services, you acknowledge that you have read, understood, and agree to the practices described herein. If you do not agree with this policy, please do not use the Services.
1. Information We Collect
We collect information in three primary ways: information you provide directly to us, information collected automatically when you interact with our Services, and publicly available or partner data.
A. Information You Provide Directly
- Account & Registration Details: When you register an account, sign in via third-party authentication providers (such as Apple or Google), or verify your profile, we collect your authentication identifiers, name, email address, optional profile avatar, and verified phone number (if provided for SMS/login verification).
- Creator Subscriptions & Fan Preferences: When you subscribe to follow a specific creator or public figure, you may choose to designate your contact information (name, handle, email, and/or mobile phone number) to receive updates. This information is associated with your subscriber profile and disclosed to that specific creator.
- Visual & Textual Search Inputs: When you conduct a search, we receive the text queries or photos you submit. As detailed below in Section 2, photos submitted solely for visual search queries are processed ephemerally in volatile memory.
- Communications & Feedback: If you contact our support team at support@whodat.app or submit platform feedback, we collect your name, email address, and the contents of your inquiry.
B. Information Collected Automatically
- Device & System Information: We collect technical diagnostic information about the devices and browsers you use, including operating system version, hardware model, mobile network details, device orientation, and platform client version.
- Usage & Diagnostic Analytics: We log user interactions such as profile navigation, searches performed, links followed, performance metrics, and application crash reports via enterprise analytics tools (e.g., Firebase Analytics, Performance Monitoring, and Crashlytics) to diagnose errors and enhance stability.
- Coarse Location (Non-GPS): We derive coarse, general geographic information (such as city, state, or region) from your IP address or from the venue location of events you browse. WhoDat does not track, request, or record continuous high-precision GPS hardware sensor coordinates from your device.
- Security & Abuse Prevention Data: We utilize risk assessment and bot-detection services (including reCAPTCHA Enterprise) to protect the Services from automated abuse, malicious traffic, and scraping.
C. Information from Third Parties and Public Knowledge Bases
WhoDat aggregates publicly available biographical facts, entity relationships, event tour dates, social media handles, and media links from public knowledge repositories, entertainment databases (such as The Movie Database - TMDB), event ticketing exchanges (such as SeatGeek, Bandsintown, and Seated), and public web directories.
2. Visual Search, Artificial Intelligence, & Biometric Privacy Notice
WhoDat uses proprietary computer vision algorithms and machine learning technologies to analyze visual features of submitted images to identify public figures and synthesize publicly available biographical information.
- Ephemeral In-Memory Processing: When you upload a photo to perform a visual search, the image is held in volatile memory (RAM) solely for the few seconds required to execute the computer vision inference and return matching public figure records. Search query images are never written to permanent disk storage, never cached in persistent file repositories, and never sold to third parties.
- No Biometric Retention of End-Users: WhoDat does not collect, scan, enroll, or retain biometric identifiers or biometric facial geometry templates belonging to our end-users. We do not use our visual search engine to identify private individuals or to surveil app users. Any facial geometry features analyzed during an automated search query exist ephemerally in RAM and are permanently discarded immediately upon query completion.
- No Model Training on User Photos: Photos uploaded by users to perform visual searches are never used to train, retrain, fine-tune, or benchmark our proprietary artificial intelligence or computer vision models.
- State Biometric Privacy Compliance (BIPA / CUBI): In accordance with the Illinois Biometric Information Privacy Act (BIPA), Texas Capture or Use of Biometric Identifier Act (CUBI), Washington RCW 19.375, and similar state privacy laws, WhoDat maintains this written policy confirming that biometric identifiers are not captured or stored for end-users, that search photo data is destroyed immediately after runtime inference, and that biometric data is never monetized, leased, or traded.
3. How We Use Information
We process collected information for legitimate business purposes and operational objectives, including:
- Delivering, maintaining, and improving the search, discovery, and profile features of the Services;
- Executing automated search queries and synthesizing biographical summaries;
- Facilitating fan subscriptions, delivering event alerts, and routing community notifications via email or SMS;
- Enabling verified creators to access subscriber lists and manage their community profiles;
- Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and enforcing our Terms of Service;
- Diagnosing crashes, monitoring infrastructure health, and optimizing application responsiveness;
- Complying with applicable legal processes, subpoenas, tax obligations, and statutory requirements.
4. How We Disclose and Share Information
WhoDat does not sell personal information to data brokers. We share information only under specific, transparent operational conditions:
- Independent Creators (Fan Subscriptions): If you choose to follow or subscribe to an individual creator and designate that you wish to share your email address and/or mobile phone number, your subscriber contact record (name, handle, email, and/or phone) is disclosed to that verified creator to enable them to connect with their audience. Creators are independent controllers of the data they receive and are contractually bound to comply with applicable marketing and privacy regulations.
- Enterprise Cloud & Infrastructure Subprocessors: We utilize trusted enterprise technology partners to host infrastructure, run secure serverless computations, deliver transactional emails and SMS, perform crash analysis, and execute automated machine learning inferences (e.g., Google Cloud Platform / Firebase and Amazon Web Services). These subprocessors are bound by data processing agreements and are prohibited from using your information for their own independent marketing purposes.
- Outbound Ticketing & Affiliate Partners: When you tap or click outbound links to purchase tickets (such as SeatGeek), stream media, or purchase creator merchandise, you are redirected to third-party merchants. We may transmit non-personal referral identifiers so that our commercial affiliate relationships are properly recorded. Your transactions on third-party sites are governed exclusively by their respective privacy policies.
- Legal Protections & Public Safety: We may disclose information if required to do so by law, subpoena, warrant, or court order, or if we determine in good faith that disclosure is necessary to investigate fraud, enforce our Terms of Service, or protect the safety, rights, or property of WhoDat, its users, or the general public.
- Corporate Transactions: In the event of a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, or sale of company assets, your personal information may be transferred as a business asset subject to standard confidentiality protections.
5. Data Retention, Security, and Account Deletion
Retention Guidelines: We retain account data (such as login credentials, profile bookmarks, and creator subscriptions) for as long as your account remains active. Operational logs and crash diagnostics are retained for standard diagnostic cycles (typically 30 to 90 days) before automated deletion.
Self-Serve Account Deletion: You have full control over your data. You may permanently delete your WhoDat account at any time directly within the mobile application by navigating to Menu → Settings → Delete Account. When you confirm account deletion:
- Your authentication credentials, account handle, and user profile documents are permanently deleted from our live databases;
- Your uploaded avatar images and saved bookmarks are purged from our cloud storage systems;
- Your subscriber records are disconnected from all followed creator rosters.
You may also submit a formal deletion or data wipe request by emailing support@whodat.app.
Security Safeguards: We implement industry-standard technical, administrative, and physical safeguards—including TLS encryption in transit, encrypted databases at rest, least-privilege cloud access controls, and automated intrusion monitoring—to protect your personal information against unauthorized access, loss, or alteration.
6. U.S. State Privacy Rights (California CPRA, Texas TDPSA, Virginia, Colorado, Utah)
Residents of California, Texas, Virginia, Colorado, Utah, and other states with comprehensive consumer privacy statutes have specific legal rights regarding their personal data:
- Right to Know and Access: The right to request disclosure of the categories and specific pieces of personal information we have collected, the sources of collection, and the business purposes for processing.
- Right to Deletion: The right to request deletion of personal information collected from you, subject to statutory exceptions (such as legal retention or fraud prevention).
- Right to Correction: The right to request rectification of inaccurate personal records.
- Notice of Non-Sale and Non-Sharing: WhoDat does not "sell" personal information as defined under the California Consumer Privacy Act (CCPA/CPRA) or other state laws, nor do we "share" personal information for cross-context behavioral advertising without consent.
- No Discrimination: We will not discriminate against you in pricing, service availability, or quality of service for exercising any of your statutory privacy rights.
To exercise your statutory rights, please submit a verified request by emailing support@whodat.app. We will verify your identity by confirming your registered email address or verified phone number prior to processing your request.
7. Children's Privacy (COPPA)
The Services are intended for a general audience and are not directed to children under 13 years of age. WhoDat does not knowingly collect, request, or solicit personal information from children under the age of 13. If we discover that a child under 13 has provided personal information without verifiable parental consent, we will promptly purge that data from our systems and terminate the associated account. If you believe a minor under 13 has provided us with personal data, please contact support@whodat.app.
8. International Data Transfers
WhoDat Ventures, Inc. is headquartered in the United States, and our servers and infrastructure are located in the United States. If you access the Services from the European Economic Area (EEA), the United Kingdom, Switzerland, or other jurisdictions with comprehensive data protection laws, please be aware that your personal information will be transferred to, processed, and stored in the United States, where data protection standards may differ from those in your home country. By using our Services, you consent to the transfer of your data to the United States.
9. Updates to This Privacy Policy
We reserve the right to modify or update this Privacy Policy from time to time to reflect changes in our legal obligations, technical architecture, or business practices. If we make material modifications, we will notify you by updating the "Last Updated" date at the top of this document and, where required by applicable law, provide prominent notice within the App or via email. Your continued use of the Services following the posting of an updated Privacy Policy signifies your acceptance of the updated terms.
10. Contact Us
If you have any questions, comments, or rights inquiries concerning this Privacy Policy or our technical privacy practices, please contact our privacy compliance team at:
WhoDat Ventures, Inc.
Attn: Privacy Officer
10063 Riverside Dr. #2182
Toluca Lake, CA 91602
Email: support@whodat.app