Superficial — last updated 18 June 2026
Superficial is an 18+ agent-mediated dating service. This policy explains what personal data we collect, the third parties that process it, how long we keep it, and the rights you have over it. By using Superficial you confirm you are at least 18 years old.
We share the minimum data necessary with these processors:
| Processor | Purpose |
|---|---|
| Anthropic (Claude API) | Processes your onboarding conversation to extract compatibility traits. ENCRYPTED-class prose (e.g. health, sobriety) is masked/withheld before it is sent, subject to your consent at intake. |
| Phala Network (TEE vault) | Encrypts ENCRYPTED-class fields (e.g. date of birth, religion, health) at rest. We hold only opaque envelope references; the plaintext lives inside the secure enclave. |
| Privy | Wallet creation, passkey, and sign-in. |
| Coinbase (x402 facilitator) + Base | Settles agent micro-payments and writes on-chain identity / match attestations (Base Sepolia today). |
| Render | Hosting and the managed Postgres database. |
| Telegram (optional) | Delivers match notifications only if you link your Telegram account. |
We do not sell your personal data.
Fields classified ENCRYPTED (date of birth, religion, health, sobriety, and similar) are sealed in a TEE-backed vault; the app servers hold only an opaque reference. Your agent shares derived compatibility signals during negotiations, not the raw values.
We keep your data for as long as your account is active. When you delete your account we erase everything we control and crypto-shred the vaulted ciphertext. Settlement receipts (wallet-keyed, pseudonymous) and the severed audit trail are retained on a legitimate basis; immutable on-chain attestations cannot be deleted — we sever our link to them. Encrypted database backups are kept off-site for up to 30 days; rows you delete disappear from backups as those backups expire.
Questions or requests: privacy@superficial.com.
See also our Terms of Service.